Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

A Recent Wave of Cyberattacks Targets Hedge Funds, Private-Equity Firms, and Financial Organizations, Linked to the BlackFile-Associated UNC6671 Extortion Group.

A coordinated wave of cyberattacks has been unleashed on hedge funds, private-equity firms, and other financial organizations in recent weeks. The attacks have been linked to an extortion group known as UNC6671, which is associated with the notorious BlackFile campaign. According to reports from Reuters and Bloomberg, several high-profile targets have already fallen victim to these attacks, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel.

The modus operandi behind these attacks is a cleverly crafted form of social engineering known as voice phishing or vishing. UNC6671 operators typically contact employees on their personal mobile phones while posing as corporate help-desks, claiming that workers need to enroll in passkeys or update their multi-factor authentication settings. Victims are then directed to domains impersonating their company, which host adversary-in-the-middle phishing kits designed to steal credentials and session cookies in real-time.

Once the attackers have gained access to Microsoft 365 or Okta single-sign-on accounts, they use automated tools to steal data from all cloud services linked to the account and delete security notifications and password-reset emails from compromised inboxes. This coordinated approach highlights the sophistication of UNC6671’s tactics and their ability to evade detection.

According to Austin Larsen, a principal threat analyst at Google’s Threat Intelligence Group (GTIG), GTIG assesses that a single core intrusion group is driving the helpdesk vishing and cloud data theft across multiple public brands, including Redact, Pink, Helix, and Falcon. This suggests that UNC6671 has diversified its extortion operations to exploit various vulnerabilities in different organizations.

The attacks have resulted in significant financial losses for the targeted companies, with reports suggesting that between January and May 2026, GTIG tracked over $10.6 million USD in Bitcoin payments to group wallets. Initial demands can reach upwards of $3 million, but operators routinely settle for around $750,000 USD after negotiations.

The fact that these attacks have been linked to UNC6671 raises concerns about the organization’s tactics and their ability to adapt to new environments. Mandiant has noted that the infrastructure and extortion network used in these attacks differ from those associated with Scattered Spider, which historically employed similar help-desk social-engineering tactics.

As a result of this threat, security teams must remain vigilant and proactive in protecting their organizations’ cloud-based assets. Regular breach and attack simulation tests can help identify vulnerabilities and ensure that detection systems are robust enough to prevent attacks like UNC6671’s from slipping through the net.


Source: Bleeping Computer — 2026-08-06