Details emerge on BlackFile’s recent attacks on financial companies

A Highly Organized Extortion Group Targets Financial Firms with Sophisticated Voice Phishing Attacks

BlackFile, a cybercrime group tracked by Google Threat Intelligence Group as UNC6671 and associated with The Com, has been wreaking havoc on financial companies, law firms, and private equity firms since the start of this year. What’s alarming is that despite being active for months, BlackFile continues to evolve its tactics, targeting new victims at an astonishing rate.

Researchers have observed that BlackFile shifts its focus from one sector to another, with a recent emphasis on the financial sector. The group’s modus operandi involves impersonating IT support through voice-phishing and social engineering attacks, which are often successful due to their clever exploitation of human weaknesses. BlackFile has divided its extortion operations into four brands with shared infrastructure: Redact, Pink, Helix, and Falcon.

Several organizations have received new extortion demands from Redact in the last week alone, according to Google. These threats typically start at $3 million but are often negotiated down to less than $1 million. BlackFile’s targets are not limited to small companies; they’re “big-game hunting,” as described by Austin Larsen, principal threat analyst at GTIG. This means that even the largest organizations in various industries, including healthcare and technology, are vulnerable.

The group’s malicious infrastructure has been observed targeting prominent financial institutions such as Blackstone, Bain Capital, Moody’s, CME, and Apollo. However, it remains unclear if any of these firms have been compromised. What is clear is that BlackFile’s steady pace of activity poses a persistent threat to organizations across multiple industries.

One of the most concerning aspects of BlackFile’s attacks is their use of hundreds of callers who are often recruited for a small fee or an opportunity to earn goodwill with the group. These callers make initial contact through voice phishing, which allows the attackers to obtain access to sensitive systems. Less than a dozen core operators are estimated to run the different brands under the BlackFile umbrella.

Mandiant incident responders have encountered BlackFile frequently, having been engaged by over two dozen organizations successfully compromised by the threat group since January. New victims in the financial sector were seeking Mandiant’s help as recently as last month.

While voice-based phishing attacks for data theft extortion are not novel or sophisticated, BlackFile and other cybercrime groups consistently demonstrate their effectiveness across virtually any sector or organization. As Larsen noted, “They’re really hitting on the human weakness element here.” This highlights the importance of educating employees about social engineering tactics and implementing robust security measures to prevent these types of attacks.

In light of this threat, it’s essential for organizations to remain vigilant and take proactive steps to protect themselves from BlackFile’s sophisticated voice phishing attacks. This includes conducting regular security awareness training for employees, implementing robust authentication protocols, and investing in incident response planning to mitigate the impact of potential breaches.


Source: CyberScoop — 2026-08-17