Threats

BlackFile Extortion Group Tied to Hedge Fund Cyberattacks

August 8, 2026 00:21 · 12 min read
BlackFile Extortion Group Tied to Hedge Fund Cyberattacks

A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors.

Background on BlackFile and UNC6671

BlackFile is a data theft extortion group that first emerged in February 2025 when it conducted a wave of attacks targeting retail and hospitality organizations. According to Mandiant's report, the group's targeting switched in July 2026 toward private-equity firms, hedge funds, major law firms, and financial-rating agencies after previously targeting organizations in the manufacturing, healthcare, real-estate, technology, transportation, and hospitality sectors.

Vishing Attacks and Cloud Environment Targets

UNC6671 operators typically contact employees on their personal mobile phones while spoofing corporate helpdesks and claiming that workers need to enroll in passkeys or update their multi-factor authentication settings. Victims are then directed to domains impersonating the targeted employee's company that host adversary-in-the-middle phishing kits designed to steal credentials and session cookies in real time.

After stealing Microsoft 365 or Okta single-sign-on accounts, the attackers log into the SSO dashboard, which gives access to all the cloud platforms that are linked to the account. The hackers then use automated tools to steal data from all cloud services they gain access to and delete security notifications and password-reset emails from compromised inboxes.

Attribution and Tracking of UNC6671

Austin Larsen, a principal threat analyst at Google's Threat Intelligence Group (GTIG), said the company tracks the vishing activity as UNC6671. "While previously operating under the public brand 'BlackFile,' UNC6671 has diversified its extortion operations across multiple public brands, including Redact, Pink, Helix, and Falcon," Larsen told BleepingComputer.

GTIG assesses that a single core intrusion group is driving the helpdesk vishing and cloud data theft across these various public extortion brands. Between January and May 2026, GTIG tracked over $10.6 million USD in Bitcoin payments to group wallets. While initial demands reach upwards of $3 million, operators routinely settle for around $750,000 USD after negotiations.

Response from the Falcon Extortion Group

After publishing the story, the Falcon extortion group released a statement on their data leak site disputing some of Mandiant's reporting. "Falcon is a Redact affiliate. We are exclusively a Redact affiliate. We are not affiliated with, connected to, or under the same umbrella as Helix, Pink, or any other group named in Mandiant's reporting," the threat actors posted on their data leak site.

In May 2026, BlackFile announced on its data leak site that it was rebranding under the name Redact, under which it would continue its operations. The Falcon extortion group stated that they share no operators, infrastructure, tooling, negotiation channels, or proceeds with any group other than Redact.

Conclusion and Recommendations

Mandiant says it is currently assisting several dozen organizations compromised by UNC6671. The company emphasizes the importance of testing every layer of security before attackers do, as security teams log 54% of successful attacks and alert on just 14%. The rest move through the environment unseen.

The Picus whitepaper shows how breach and attack simulation tests SIEM and EDR rules so threats stop slipping by detection. It is essential for organizations to stay vigilant and take proactive measures to protect themselves against such threats.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free