A notorious cybercrime group, BlackFile, has been wreaking havoc on financial companies and other organizations across multiple industries. According to researchers at Google Threat Intelligence Group (GTIG), this threat actor has been active since the start of 2026, targeting victims with ease and extorting them for millions of dollars.
BlackFile’s modus operandi is a perfect example of how cybercrime groups exploit human psychology. The group impersonates IT support through voice-phishing calls, convincing targets to give up sensitive information or install malware on their systems. What’s more alarming is that BlackFile has recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix, and Falcon. This fragmentation allows the group to present a confusing picture of itself, making it harder for victims to pinpoint the source of the attacks.
As we delve deeper into the workings of BlackFile, it becomes clear that this is not just any ordinary cybercrime group. They have a sophisticated approach, targeting some of the largest organizations in various sectors, including healthcare, technology, and finance. GTIG’s principal threat analyst, Austin Larsen, noted that BlackFile “does go after some of the largest organizations in the sectors that they go for. They’re not going after small companies. This is big-game hunting.” The group’s extortion demands often start at $3 million, but payments have been negotiated down to less than $1 million in many cases.
Researchers have observed malicious infrastructure targeting prominent financial institutions like Blackstone, Bain Capital, Moody’s, CME, and Apollo. However, it remains unclear whether these firms were compromised. What is certain, though, is that BlackFile has a steady pace of activity, averaging 1.5 new victims per day. This persistence underscores the threat it poses to organizations worldwide.
One of the most striking aspects of BlackFile’s operations is their use of hundreds of callers, often recruited for a small fee or an opportunity to earn goodwill with the group. These callers make voice-phishing calls to obtain initial access, which is then used to extort victims. Mandiant incident responders have encountered BlackFile frequently, having been engaged by over two dozen organizations successfully compromised by the threat group since January.
The effectiveness of BlackFile’s tactics lies in their ability to exploit human weaknesses. As GTIG’s Austin Larsen noted, “They’re really hitting on the human weakness element here.” Voice-based phishing attacks for data theft extortion may not be sophisticated or novel, but BlackFile and other cybercrime groups consistently prove their continued effectiveness across virtually any sector or organization.
For organizations and individuals alike, this serves as a stark reminder of the importance of cybersecurity awareness. The takeaway from this story is clear: employees must be educated to recognize and resist phishing attempts, especially those that impersonate IT support. By being vigilant and proactive in addressing these threats, we can reduce our exposure to cybercrime groups like BlackFile.
Source: CyberScoop — 2026-08-17