Threats

BlackFile Cyberattacks Target Financial Sector

August 18, 2026 12:10 · 12 min read
BlackFile Cyberattacks Target Financial Sector

BlackFile's Recent Attacks on Financial Companies

A cybercrime group known as BlackFile, tracked by Google Threat Intelligence Group as UNC6671, has been active since the start of the year, targeting various sectors including financial, law firms, and financial rating agencies.

According to Austin Larsen, principal threat analyst at GTIG, BlackFile has continued to target the financial sector, with additional targeting of organizations in the med tech space. The group impersonates IT support in voice-phishing and social engineering attacks, and has recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix, and Falcon.

Extortion Demands and Payments

Several organizations received new extortion demands from Redact in the last week, with demands often starting around $3 million. However, payments, including several in the past few weeks, have typically been negotiated down to less than $1 million, according to Google.

BlackFile's steady pace of activity underscores the persistent threat it poses, as it targets an average of 1.5 new victims daily, researchers said. Some of the group's recent victims have been subject to threatening messages and other forms of escalation, including swatting incidents.

Malicious Infrastructure and Targets

Flashpoint researchers have observed malicious infrastructure targeting Blackstone, Bain Capital, Moody's, CME, and Apollo, but it's unclear if any of those firms were compromised. BlackFile's affiliates have impacted organizations in multiple industries, including healthcare, technology, transportation, logistics, wholesale, retail, and hospitality.

Larsen estimates that less than a dozen core operators run the different brands under the BlackFile umbrella, using hundreds of callers, often lower-level people recruited for a small fee or an opportunity to earn goodwill with the group, to make voice-phishing calls and obtain initial access.

Response and Effectiveness

Mandiant incident responders have encountered BlackFile often, having been engaged by more than two dozen organizations successfully compromised by the threat group since January. New victims in the financial sector were calling Mandiant in for help earlier this month.

Voice-based phishing attacks for data theft extortion may not be sophisticated or novel, but BlackFile and other cybercrime groups consistently prove their continued effectiveness across virtually any sector or organization, exploiting human weakness.

They're really hitting on the human weakness element here, said Larsen.

As the threat landscape continues to evolve, it's essential for organizations to remain vigilant and proactive in their cybersecurity measures, recognizing the persistent threat posed by groups like BlackFile.

With the group's ability to adapt and evolve, it's crucial for companies to prioritize employee education and awareness, implementing robust security protocols to prevent initial access and minimize the risk of successful extortion attempts.

As researchers continue to monitor BlackFile's activities, one thing is clear: the group's steady pace of activity and ability to exploit human weakness make it a formidable threat to organizations across various sectors.

Organizations must remain aware of the tactics, techniques, and procedures (TTPs) used by BlackFile and other cybercrime groups, staying informed about the latest threats and vulnerabilities to ensure the security and integrity of their systems and data.

Conclusion

In conclusion, BlackFile's recent attacks on financial companies highlight the importance of robust cybersecurity measures and employee awareness. As the threat landscape continues to evolve, it's essential for organizations to prioritize proactive security protocols and remain vigilant in the face of persistent threats like BlackFile.

By understanding the tactics and techniques used by BlackFile and other cybercrime groups, organizations can better protect themselves against the ever-present threat of cyberattacks and extortion attempts.

Ultimately, the key to preventing successful cyberattacks lies in a combination of robust security protocols, employee education, and awareness, as well as a deep understanding of the threat landscape and the tactics used by groups like BlackFile.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free