6 min read

New Name, Same Playbook: How a Vishing Crew Climbed From Retail to Wall Street in 18 Months- 307

New Name, Same Playbook: How a Vishing Crew Climbed From Retail to Wall Street in 18 Months- 307

August 11, 2026

A criminal group that spent early 2025 attacking retail and hospitality chains does not, under ordinary circumstances, end up a year and a half later inside the networks of Point72, Millennium Management, Two Sigma, and Citadel. Google's Threat Intelligence Group tracks the actor behind that climb as UNC6671, and its trajectory is less a story about a single dramatic breach than about a criminal operation visibly getting better at its job — broadening its target list, laundering its own reputation through repeated rebranding, and refining a negotiation playbook precise enough to produce the same outcome in the majority of cases, all while keeping its actual technical method almost entirely unchanged.

The group first surfaced in February 2025 under the name BlackFile, running a wave of attacks against retail and hospitality organizations — a target profile with real but limited payout potential. Mandiant's tracking shows a deliberate broadening from there: through the following year, the same operators moved into manufacturing, healthcare, real estate, technology, and transportation, before making a sharp and evidently deliberate pivot in July 2026 toward private-equity firms, hedge funds, major law firms, and financial-rating agencies — organizations chosen specifically for the concentration of high-value financial and client data they hold. That progression reads like a criminal enterprise testing its method against progressively harder and more lucrative targets, gaining confidence and refining its approach at each stage rather than gambling everything on a single leap to the top of the market.

The rebranding that accompanied this climb looks, on its face, like exactly the kind of instability that should make a threat actor easier to track, not harder. BlackFile retired its own name in May 2026, and its operations have continued since under at least four public brands — Redact, Pink, Helix, and Falcon — with the Redact brand specifically launching a new data-leak site that month while publicly claiming BlackFile's operation had been "hijacked by an affiliate," a framing that lets the group discard a name accumulating law-enforcement attention while quietly continuing the same underlying work. GTIG's own assessment is appropriately cautious about what that multi-brand structure actually represents: overlapping digital footprints support treating BlackFile, Redact, Pink, Helix, and Falcon as products of a common core group, but the analysts are explicit that splintered affiliates or shared phishing-as-a-service infrastructure remain plausible alternative explanations, rather than collapsing the uncertainty into a tidier conclusion than the evidence supports. One of the named brands pushed back directly: Falcon posted a statement on its own data-leak site insisting it is "exclusively a Redact affiliate," sharing no operators, infrastructure, tooling, negotiation channels, or proceeds with Helix, Pink, or any other group named in Mandiant's reporting — a rare instance of the threat actors themselves publicly contesting how researchers have grouped them, and a reminder that even confident attribution assessments in this space are working from outside the room. Redact itself was more candid about the whole enterprise on its own darknet site, stating plainly that its hackers "are not politically or morally motivated" — a description that at least has the virtue of being honest about the business model underneath the rebranding.

What hasn't changed at all, across every rebrand and every step up the target ladder, is the technical method itself, and its effectiveness depends entirely on a human decision rather than a software flaw. UNC6671 operators call employees directly on their personal mobile phones, spoofing legitimate corporate helpdesk numbers and inventing an urgent pretext — typically a mandatory passkey enrollment or multi-factor authentication update — to walk the victim through a spoofed login portal that harvests credentials and session cookies in real time using adversary-in-the-middle phishing kits. Once the attackers have a working Microsoft 365 or Okta single sign-on session, the payoff is structural rather than incremental: logging into the SSO dashboard hands them access to every cloud platform linked to that one account, at which point automated tools sweep data from all of them simultaneously, while the operators delete security notifications and password-reset emails from the compromised inbox to buy themselves time before anyone notices. Recent attacks have added a further refinement — spoofing legitimate helpdesk phone numbers specifically, and using compromised email access to reset passwords on non-SSO enterprise applications the initial SSO compromise wouldn't otherwise reach. GTIG is careful to distinguish this from the superficially similar helpdesk-vishing tactics historically associated with Scattered Spider (UNC3944): the surface technique looks alike, but the infrastructure, domain-registration patterns, and multi-brand extortion network tracked as UNC6671 are assessed as a separate operation entirely, a distinction that matters for anyone tempted to treat all helpdesk-vishing incidents as the work of one actor.

The financial results of this campaign show the same maturation as the target selection. Between January and May 2026 alone, GTIG tracked 141.65 Bitcoin — worth roughly $10.69 million — moving into eighteen group-controlled wallets, with payments continuing even after the public BlackFile shutdown announcement, undercutting the idea that the rebrand represented any real interruption in operations. The negotiation pattern behind those payments looks less like improvisation than a repeatable formula: initial demands typically open between $1 million and upwards of $3 million, operators then concede 50 to 75 percent of that figure during negotiation, and in more than half of tracked cases, the final payment settled at an average of $750,000 — a level of consistency across victims that suggests a deliberate, tested negotiating range rather than each demand being set from scratch. Google itself declined to name any victims by name, but Reuters reverse-engineered much of the target list by running the 72 malicious websites Google did disclose through the web-intelligence platforms DomainTools and urlscan, which surfaced company-specific credential-harvesting subdomains — patterns like [company].createssopasskey[.]com or [company].addssopasskey[.]com — tailored to each individual firm being targeted. That work identified digital traps built for more than 200 companies over a five-week span, a list that reaches well beyond the hedge funds already in the public record to include Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, Moody's, Uber, Zillow, and law firms including Paul Hastings and Greenberg Traurig. The named outcomes span the full range a campaign at this scale would predict: Point72 confirmed it had been attacked but found no evidence client data was stolen, Two Sigma said it blocked an intrusion attempt outright with no systems or data affected, Greenberg Traurig stated it suffered no breach thanks to its own security protocols, and Millennium and Citadel each declined to comment beyond referring reporters to prior coverage — outcomes ranging from a clean block to an unconfirmed but acknowledged breach, at some of the most sophisticated and well-resourced financial institutions in the world. Mandiant says it is currently assisting several dozen organizations compromised by the group, a scale that makes clear the hedge-fund attacks are not an isolated escalation but the current leading edge of a campaign still actively running.

One of those 200-plus targeted companies, Levi Strauss, offers a rare look at what a successful compromise in this campaign actually looks like from inside a victim's own disclosure. In a regulatory filing, the denim maker said intruders used social engineering to gain access to three employees' work computers and exfiltrated what it described only as "certain corporate information." Levi's said it detected the intrusion, activated its incident response process, brought in outside cybersecurity specialists, and cut off the unauthorized access, with its investigation still ongoing at the time of disclosure; the company's preliminary findings indicate no consumer data was affected, no disruption to operations occurred, and it does not currently expect a material impact on its business. There is no public confirmation that UNC6671 specifically was behind the Levi's intrusion, and the company has not said what was taken or whether attackers attempted to extort it — but the shape of the incident, three individual employees' machines compromised through social engineering rather than any technical exploit, matches the campaign's method exactly, and Levi's containment before attackers went deeper is as close to a best-case outcome as this kind of intrusion gets.

What UNC6671's trajectory ultimately demonstrates is that a criminal operation can mature significantly — broadening its targets, layering its reputation behind disposable brand names, and standardizing its extortion economics into a repeatable negotiation range — without needing to improve its actual intrusion technique at all. The vishing call, the spoofed passkey-enrollment pretext, and the AiTM credential theft that got the group into retail chains in February 2025 are the same mechanisms that got it into some of the best-defended financial firms in the industry eighteen months later. The rebranding confuses investigators and lets the group discard accumulated notoriety, and the escalating negotiation sophistication maximizes revenue per victim, but the actual vulnerability being exploited throughout is unchanged: an employee on a personal phone, being asked to act urgently by someone who sounds exactly like the help desk they already trust.