Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group.
Intelligence analysis by Llama

A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group. The attackers use voice phishing (vishing) to trick employees into granting them access to corporate systems.
Imagine someone calls you on your phone, pretending to be from your company's help desk. They tell you that you need to update your security settings, but really, they're trying to trick you into giving them access to your company's computer system. This is called a vishing attack, and it's how the UNC6671 group is stealing money from companies.
Analysis
UNC6671: The Extortion Group Behind the Attacks
UNC6671 is an extortion group reportedly associated with the BlackFile campaign extortion group. The group has diversified its extortion operations across multiple public brands, including Redact, Pink, Helix, and Falcon. According to Google's Threat Intelligence Group (GTIG), a single core intrusion group is driving the helpdesk vishing and cloud data theft across these various public extortion brands.
Vishing Attacks Target Cloud Environments
UNC6671 operators typically contact employees on their personal mobile phones while spoofing corporate help-desks and claiming that workers need to enroll in passkeys or update their multi-factor authentication settings. Victims are then directed to domains impersonating the targeted employee's company that host adversary-in-the-middle phishing kits designed to steal credentials and session cookies in real time.
The Impact of the Attacks
The attacks have resulted in significant financial losses for the targeted organizations. Between January and May 2026, GTIG tracked over $10.6 million USD in Bitcoin payments to group wallets. While initial demands reach upwards of $3 million, operators routinely settle for around $750,000 USD after negotiations.
Test Every Layer Before Attackers Do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Key points
- UNC6671 is an extortion group reportedly associated with the BlackFile campaign extortion group.
- The group uses vishing attacks to trick employees into granting them access to corporate systems.
- The attacks have resulted in significant financial losses for the targeted organizations.
- Between January and May 2026, GTIG tracked over $10.6 million USD in Bitcoin payments to group wallets.
If the targeted organizations can improve their security measures and detect these vishing attacks earlier, they may be able to prevent the attackers from gaining access to their systems and stealing sensitive information.
If the attackers continue to use vishing attacks to gain access to corporate systems, they may be able to steal sensitive information and cause significant financial losses for the targeted organizations.



