VMTech
Discuss a project

UNC6671 vishing campaign steals SaaS access through personal phones

UNC6671 vishing campaign steals SaaS access through personal phones

Google Threat Intelligence Group (GTIG) and Mandiant have attributed a recent campaign against financial services, private equity and professional-services organizations to the data-extortion group UNC6671. The operators use voice phishing, or vishing, to impersonate IT help-desk staff and frequently call employees on their personal mobile phones.

The calls present an urgent, mandatory security migration and direct targets to spoofed login portals. Those adversary-in-the-middle pages intercept credentials and multi-factor authentication tokens, after which the attackers establish session persistence and run automated Python and PowerShell scripts to exfiltrate data from enterprise cloud environments and SaaS applications, including Microsoft 365 and Okta.

Identity access becomes the entry point

CrowdStrike, which tracks the collective as Cordial Spider, said the group creates urgency around account problems or security updates to draw victims to fraudulent authentication pages. Captured credentials and active session tokens can give the intruders access to an organization’s identity provider, creating a single entry point to connected SaaS services.

The group may then register adversary-controlled MFA devices on compromised accounts after removing existing devices. By exploiting the trust relationship between an identity provider and connected services, attackers can move across a SaaS environment without separately compromising every application. This pattern echoes the focus on exploited trust described in borrowed trust tactics in cybersecurity, where identity and access pathways provide the meaningful operational context for defending cloud services.

Brands, infrastructure and extortion economics

GTIG said UNC6671 has used several public extortion brands, including Redact, Pink, Helix and Falcon. It had previously operated under the BlackFile brand, which was retired on May 11, 2026. Google first documented UNC6671 in January 2026 and noted similarities with tradecraft associated with ShinyHunters, while assessing that the operations act independently.

Some credential-harvesting panels use generic root domains related to passkeys, MFA or SSO, with victim-specific subdomains added for targeted calls. GTIG also observed attackers using compromised email accounts to trigger password resets for non-SSO applications and delete reset confirmations and security alerts.

Between January 7 and May 12, 2026, Google tracked more than $10.6 million in Bitcoin payments to wallets associated with the group. Initial demands exceeded $3 million, but negotiations produced reductions of 50% to 75%; in more than 53% of tracked cases, settlements averaged $750,000.

Controls that address the campaign

Google stressed that these compromises do not result from a vulnerability in vendor products or infrastructure. The campaign instead demonstrates the effectiveness of social engineering against SaaS and identity workflows.

Organizations should enforce phishing-resistant MFA, connect SaaS applications and cloud platforms to SSO, apply session controls and limit authentication to trusted network sources. Requiring corporate-managed devices, reviewing identity-provider logs for suspicious MFA registrations and alerting when corporate password hashes are submitted to unauthorized domains provide practical controls against this vishing-driven access path.

#cybersecurity#vishing#saassecurity#identitysecurity
Open analytics
On the site 0 views
min read 4 07.08.2026
Instagram

UNC6671 vishing campaign steals SaaS access through personal phones

Open the post on Instagram ↗