# The Helpdesk Didn't Call. UNC6671 Did — and Wall Street Picked Up.
The call comes in on your personal cell, not your work line. The caller ID looks like your company's IT department. The voice on the other end is calm, authoritative, helpful: there's a security update underway, you need to re-enroll your passkey or reset your MFA before the end of the day. All you have to do is click this link.
You're a compliance analyst at a hedge fund. You do what the helpdesk says.
That's how UNC6671 walked into Point72 Asset Management, Two Sigma Investments, Millennium Management, Citadel, and a string of private-equity firms over the past several weeks. Google's Threat Intelligence Group confirmed the attribution after Reuters and Bloomberg broke the initial reporting — and what GTIG described is a group that has quietly become one of the most methodical extortion operations targeting financial services.
## A Brand Rotation Strategy, Not a Hacker Group
Most threat actors build a brand. UNC6671 burns them.
You may know this group as BlackFile, which surfaced in February 2025 running smash-and-grab data theft operations against retailers and hospitality chains. What Mandiant has now documented is that BlackFile was never really a group — it was a label. The same core intrusion team operates simultaneously under at least four public extortion brands: Redact, Pink, Helix, and Falcon, with BlackFile serving as an earlier iteration.
This is deliberate. Multi-brand operations fragment attribution, confuse defenders, and buy time. When one brand generates too much heat — law enforcement attention, researcher coverage, ransom payment resistance from targets who've been warned — the group simply lifts the tent and reassembles under a different name. The infrastructure and personnel are continuous. The identity is disposable.
GTIG tracked over $10.6 million in Bitcoin payments to group wallets between January and May 2026 alone. Initial demands reach as high as $3 million, but the operators routinely negotiate down to around $750,000. It's not chaos — it's a pricing strategy with room built in for haggling.
## The Pivot to Finance Wasn't Random
Between early 2025 and mid-2026, UNC6671 worked its way through manufacturing, healthcare, real estate, technology, transportation, and hospitality. These aren't random sectors — they're firms that hold sensitive data but historically have weaker security programs and less sophisticated IR capability than financial institutions.
Then, in July 2026, the targeting changed. Hedge funds, private-equity firms, major law firms, financial-rating agencies. The jump is significant. These organizations have more mature security teams, larger budgets, and more to lose reputationally — but they also have richer data and, critically, higher willingness to pay to make a breach go away quietly.
The group is learning. Every sector they work through is a training ground for the next.
## How the Vishing Actually Works
The technical execution is what makes this genuinely difficult to defend against.
UNC6671 operators call employees on their *personal* mobile phones, not corporate lines. This matters because personal phones are typically outside corporate call filtering, MDM policy, and security monitoring. The caller ID is spoofed to match the company's IT help desk.
The script centers on urgency and legitimacy: employees are told they need to enroll in passkeys or update their MFA configuration. This framing is particularly cruel because it turns the security control itself into the attack vector. Employees who do the right thing — comply with what sounds like a security directive — are the ones who get compromised.
When the victim visits the provided link, they hit an adversary-in-the-middle phishing kit that harvests credentials and session cookies in real time. Once the attacker has an active Microsoft 365 or Okta session, they're inside the SSO dashboard — and from there, every connected cloud application is exposed. Automated tools sweep the environment for data while the attackers delete security alerts and password-reset notifications from the compromised inbox to buy themselves time.
## Not Scattered Spider, But Adjacent
Mandiant went out of its way to distinguish UNC6671 from Scattered Spider (UNC3944), and the distinction matters. The tactics — helpdesk vishing, AiTM phishing, SSO pivoting — are nearly identical. But the infrastructure, domain registration patterns, and multi-brand extortion network are distinct.
What this means in practice: there are now at least two sophisticated threat actors running the same playbook at scale against enterprise targets. The Scattered Spider arrests in 2024 and 2025 didn't kill the tradecraft. They may have taught it to more people.
---
## HackWire Analysis
The most underreported aspect of this wave of attacks is what the targeting pivot to hedge funds tells us about the group's operational maturity — and what it signals for financial services firms that haven't been hit yet.
UNC6671 isn't a ransomware-as-a-service affiliate operation spraying payloads at anything that moves. It's a disciplined extortion shop that spent over a year working smaller targets before systematically moving upmarket. The move to hedge funds and PE firms in July 2026 looks like a deliberate escalation triggered by two factors: successful negotiations in prior verticals that proved the model works, and the recognition that financial firms — despite better security — are extraordinarily motivated to avoid disclosure.
The regulatory environment makes this worse. A hedge fund that reports a breach risks investor redemptions. A PE firm that discloses data theft from portfolio company systems risks deal flow. The structural incentives toward quiet settlement are enormous, which is exactly why $750,000 is a rational price to pay to make a problem disappear — even if paying funds more operations.
The vishing angle deserves more attention from defenders than it's getting. Phishing awareness training has become standard. Vishing training has not. Most employees have never practiced recognizing a spoofed helpdesk call. The adversary knows this. The immediate defensive priority isn't a new technical control — it's a single policy: any call requesting MFA re-enrollment or credential action should be verified via a callback to an internal directory, never the number that called you.
Mandiant says it's currently assisting dozens of compromised organizations. The real number is almost certainly higher. Most won't announce it.
— HackWire Editorial
---
## Related Coverage