A wave of cyberattacks targeting major hedge funds and private-equity firms — including Point72, Millennium Management, Two Sigma, and Citadel — has been attributed to UNC6671, an extortion group linked to the BlackFile campaign. Google's Threat Intelligence Group (GTIG) tracks the group, which has operated under multiple brands including Redact, Pink, Helix, and Falcon. Attackers use voice phishing (vishing) to impersonate corporate help desks, directing employees to adversary-in-the-middle phishing sites that steal Microsoft 365 and Okta SSO credentials and session cookies. Once inside, automated tools exfiltrate data from all linked cloud services. Between January and May 2026, GTIG tracked over $10.6 million in Bitcoin payments to the group, with initial demands up to $3 million typically settling around $750,000. Mandiant is currently assisting several dozen compromised organizations and distinguishes UNC6671's infrastructure from the similarly-styled Scattered Spider group.
Questions this post answers
What tactics does the UNC6671 extortion group use to compromise corporate cloud accounts?
UNC6671 operators call employees on personal mobile phones while spoofing corporate help desks, claiming workers need to enroll in passkeys or update MFA. Victims are directed to adversary-in-the-middle phishing sites that steal Microsoft 365 or Okta SSO credentials and session cookies in real time. Attackers then log into the SSO dashboard and use automated tools to exfiltrate data from all linked cloud services. Security teams defending cloud SSO environments track emerging vishing campaigns like this on daily.dev.
How much has UNC6671 collected in ransom payments and what are their typical demands?
Between January and May 2026, GTIG tracked over $10.6 million USD in Bitcoin payments to UNC6671 wallets. Initial ransom demands reach upwards of $3 million, but operators routinely settle for around $750,000 USD after negotiations. Threat intelligence on active extortion groups and their financials surfaces regularly for security practitioners on daily.dev.
How is UNC6671 different from Scattered Spider and are they the same group?
UNC6671 and Scattered Spider (UNC3944) are distinct groups. While both use help-desk vishing and adversary-in-the-middle authentication interception, Mandiant's GTIG distinguishes UNC6671 by its specific infrastructure, domain registration patterns, and multi-brand extortion network operating under names like BlackFile, Redact, Pink, Helix, and Falcon. Defenders tracking threat actor distinctions like this find attribution updates across the security space on daily.dev.