Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Swiss government SharePoint breach compromised 200 accounts

    August 6, 2026

    Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

    August 6, 2026

    InfoSec News Nuggets – 08/06/2026

    August 6, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
    News

    Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

    adminBy adminAugust 6, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Extortion gang

    A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group.

    The attribution comes after Reuters and Bloomberg reported that Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and several private-equity firms were targeted in recent attacks that relied on voice phishing (vishing) to trick employees into granting the attackers access to corporate systems.

    Point72 reportedly told investors that it had been attacked but had not found evidence that client data was stolen, while Two Sigma said it had blocked an attempted intrusion and found no indication that its systems or data were affected.

    image

    Millennium declined to comment in response to questions from BleepingComputer. Citadel also declined to comment and referred BleepingComputer to Bloomberg’s reporting. Point72 and Two Sigma did not respond to requests for comment.

    In response to questions from BleepingComputer, Austin Larsen, a principal threat analyst at Google’s Threat Intelligence Group (GTIG), said the company tracks the vishing activity as UNC6671.

    “While previously operating under the public brand ‘BlackFile,’ UNC6671 has diversified its extortion operations across multiple public brands, including Redact, Pink, Helix, and Falcon,” Larsen told BleepingComputer.

    “GTIG assesses that a single core intrusion group is driving the helpdesk vishing and cloud data theft across these various public extortion brands.”

    BlackFile is a data theft extortion group that first emerged in February 2025 when it conducted a wave of attacks targeting retail and hospitality organizations.

    According to Mandiant’s report, the group’s targeting switched in July 2026 toward private-equity firms, hedge funds, major law firms, and financial-rating agencies after previously targeting organizations in the manufacturing, healthcare, real-estate, technology, transportation, and hospitality sectors.

    “Between January and May 2026, GTIG tracked over $10.6 million USD in Bitcoin payments to group wallets. While initial demands reach upwards of $3 million, operators routinely settle for around $750,000 USD after negotiations,” Larsen said.

    Vishing attacks target cloud environments

    UNC6671 operators typically contact employees on their personal mobile phones while spoofing corporate help-desks and claiming that workers need to enroll in passkeys or update their multi-factor authentication settings.

    Victims are then directed to domains impersonating the targeted employee’ company that host adversary-in-the-middle phishing kits designed to steal credentials and session cookies in real time.

    After stealing Microsoft 365 or Okta single-sign-on accounts, the attackers log into the SSO dashboard, which gives access to all the cloud platforms that are linked to the account.

    Okta SSO account
    Okta SSO dashboard with access to many cloud platforms

    The hackers then use automated tools to steal data from all cloud services they gain access to and delete security notifications and password-reset emails from compromised inboxes.

    Mandiant says the infrastructure and extortion network used in these attacks differ from those associated with Scattered Spider, which has historically employed similar help-desk social-engineering tactics.

    “While the helpdesk vishing and Adversary-in-the-Middle authentication interception share similarities with methods historically associated with Scattered Spider (UNC3944), GTIG tracks this specific infrastructure, domain registration pattern, and multi-brand extortion network as UNC6671,” Larsen told BleepingComputer.

    Mandiant says it is currently assisting several dozen organizations compromised by UNC6671.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleInfoSec News Nuggets – 08/06/2026
    Next Article Swiss government SharePoint breach compromised 200 accounts
    admin
    • Website

    Related Posts

    News

    Swiss government SharePoint breach compromised 200 accounts

    August 6, 2026
    News

    InfoSec News Nuggets – 08/06/2026

    August 6, 2026
    News

    The OSINT Newsletter – Issue #117

    August 6, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Our Picks

    Swiss government SharePoint breach compromised 200 accounts

    August 6, 2026

    Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

    August 6, 2026

    InfoSec News Nuggets – 08/06/2026

    August 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.