# One Phone Call. Every SaaS App You Own.
The trick isn't clever malware. It's a call to your personal cell, a fake IT voice, and a spoofed login page — and by the time you realize what happened, attackers have your Microsoft 365 session, your Okta credentials, and a backdoor into every cloud service your company runs.
That's the playbook for UNC6671, a data extortion group that Google Threat Intelligence Group and Mandiant formally documented this week after months of attacks against financial services firms, private equity shops, and professional services companies across North America, Australia, and the UK.
## They're Calling Personal Phones. That's Not an Accident.
The social engineering hook starts with a call to an employee's personal mobile — not their work phone. That distinction is deliberate. Corporate devices often carry MDM software, security profiles, and call screening. Personal phones have none of that. The employee picks up, hears a plausible IT voice announcing an urgent security migration requiring immediate action, and they're already off-balance before a word gets typed.
UNC6671 operators pose as help desk staff facilitating mandatory account migrations or security updates. The urgency framing is textbook: "Your account will be locked in four hours." "This is required before end of business today." Victims get directed to spoofed login portals sitting on adversary-in-the-middle (AitM) infrastructure that doesn't just steal credentials — it captures the MFA token in real time, while the authentication is happening.
This is what makes modern AitM so much more dangerous than classic phishing. Traditional phishing steals a password. AitM proxies the entire authentication session, so the attacker walks away with a live, authenticated session cookie. TOTP codes that expire in 30 seconds are useless against this approach — the attacker's infrastructure relays the victim's input to the real login service and hands back the session. The victim thinks they logged in normally.
## The IdP Is the Master Key
Here's where the attack becomes surgically efficient. UNC6671 doesn't target individual SaaS applications. They target identity providers — Okta, Microsoft Entra ID — and let the IdP do the heavy lifting.
Once inside an organization's IdP with a valid session, the attacker gains single-sign-on access to every application federated to it. Microsoft 365, Salesforce, Workday, Slack, GitHub, cloud storage — anything wired through the identity provider becomes accessible without touching a vulnerability in any of those products. CrowdStrike, which tracks this group as Cordial Spider, put it plainly: attackers "bypass the need to compromise individual SaaS apps and instead move laterally across the victim's entire SaaS ecosystem with a single authenticated session."
The first move after entry is persistence. Attackers register an adversary-controlled MFA device to the compromised account — removing the victim's existing MFA devices first. By the time IT notices something is wrong, the attacker holds a fresh foothold and the legitimate user has been locked out of their own account.
Then come the automated scripts: Python and PowerShell pipelines exfiltrating whatever is valuable — financial records, client data, deal flow, communications. The operation runs fast. GTIG and Mandiant describe UNC6671 as maintaining a "high operational cadence," which tracks with the victim profile. Private equity and financial services firms have high-value, concentrated data — and workforces conditioned to respond urgently to IT requests.
## A Group That Changes Brands to Stay Alive
UNC6671 surfaced in early January 2026 and launched its BlackFile data leak site in February. By late April, BlackFile was offline. By May 19, the Redact brand had formally announced that BlackFile operations were "officially and permanently ceased." Since then, Pink, Helix, and Falcon have also appeared as extortion brands operating under the same umbrella.
This brand cycling isn't unique — Scattered Spider affiliates have run similar pivots — but UNC6671's pace is aggressive. A June claim that BlackFile had been "hijacked by a former associate" running unsanctioned campaigns added a layer of internal dispute narrative that muddied the water for researchers and defenders trying to track attribution. Whether that claim is true doesn't matter much operationally; the confusion it creates does.
CrowdStrike bundles this activity under Cordial Spider as an overarching collective. Google assesses that while UNC6671's tradecraft resembles ShinyHunters (Bling Libra), the groups are operating independently. That split matters for attribution but doesn't change the attack geometry defenders are actually facing.
## HackWire Analysis
What makes UNC6671 worth watching closely isn't just the technique — it's the structural gap they're exploiting, and how deliberately they've built around it.
Most enterprise security programs are designed around protecting corporate devices and corporate networks. They hardened those perimeters over a decade of effort. But the employee's personal iPhone sits entirely outside that perimeter. It has no MDM, no corporate DNS filtering, no call screening, and — critically — it's the device many organizations use for MFA delivery. BYOD policies gave attackers that gap. UNC6671 saw it and built their entire operation around it.
The immediate defensive advice from GTIG — move toward phishing-resistant MFA — is correct, but the implementation detail matters enormously. FIDO2 and passkeys have to be enforced at the IdP level with no TOTP or SMS fallback. Any fallback is the attack surface. Financial services and PE firms especially should audit which applications still accept token-based MFA as an alternative path and close those exceptions now, not after the next incident report.
The brand cycling signals longevity planning. Each pivot insulates the group from infrastructure burns and makes threat intelligence tied to a specific brand name less actionable within weeks. Organizations waiting on government advisories keyed to "BlackFile" or "Redact" are already behind. Track the TTPs — personal device vishing, AitM portals, IdP session persistence — not the logo.
The detail getting almost no coverage is the MFA device registration step. A breached organization that remediates the initial compromise but fails to audit MFA devices registered during the intrusion window will find the attackers still have re-entry. Any incident response engagement touching UNC6671 or Cordial Spider activity should include a full audit of MFA devices registered in the last 90 days, with re-enrollment required from trusted endpoints for every account that was touched. That's not optional hygiene — it's the specific step that closes the backdoor this group intentionally leaves behind.
— HackWire Editorial
## Related Coverage