UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A New Wave of Vishing Attacks Exploits Personal Phones to Steal SaaS Data, Leaving Millions Exposed

A sophisticated wave of vishing (voice phishing) attacks has been targeting individuals’ personal phones, aiming to steal sensitive data from Software as a Service (SaaS) applications. According to reports, the UNC6671 threat actor group is behind these campaigns, which have already compromised millions of users worldwide.

The modus operandi of these attacks involves manipulating victims into revealing their SaaS login credentials over the phone. Once obtained, the attackers use this information to access the targeted accounts, exploiting the privilege escalation vulnerabilities inherent in many SaaS platforms. This allows them to move laterally within the affected organization’s digital environment, compromising sensitive data and exposing it to further exploitation.

The attacks work by using social engineering tactics to trick victims into divulging their login credentials. Attackers posing as IT support or other authorized personnel call or message the target, creating a sense of urgency or legitimacy that coerces them into providing sensitive information. In many cases, these compromised accounts are used for cross-domain privilege escalation, enabling the attackers to move undetected across multiple systems and applications.

The scope of this threat is vast, with SaaS platforms being a common entry point for malicious actors due to their widespread adoption and relatively lax security standards. The UNC6671 group has demonstrated a clear understanding of these vulnerabilities, exploiting them to devastating effect. As a result, millions of users are at risk of having their sensitive data compromised.

The ease with which these attacks can be carried out underscores the need for greater awareness among SaaS users regarding the risks associated with vishing and other social engineering tactics. It is essential that individuals remain vigilant when receiving unsolicited calls or messages, particularly those requesting sensitive information over the phone. Furthermore, SaaS providers must prioritize implementing robust security measures to prevent cross-domain privilege escalation and protect their users from these types of attacks.

To mitigate this risk, it’s crucial for individuals to be cautious when interacting with unknown callers or message senders. Never provide sensitive information over the phone unless you are certain of the authenticity of the request. SaaS providers should also ensure that they have implemented multi-factor authentication (MFA) and other robust security measures to prevent unauthorized access to user accounts. By staying informed and taking proactive steps, users can reduce their exposure to these types of attacks and protect themselves from the devastating consequences of a data breach.


Source: The Hacker News — 2026-08-07