UNC6671 Profile: Vishing targets personal phones to steal SaaS data

A new wave of attacks targeting financial organizations, private equity firms, and professional services is being attributed to UNC6671, a data-extortion group linked to the BlackFile ecosystem. The notable point is not complex malware, but how the group combines fraudulent phone calls, session hijacking, and employees' habit of working from personal phones.

UNC6671 uses vishing to target finance employees and SaaS data

According to The Hacker News, UNC6671 often impersonates IT support to pressure employees into completing what appears to be an urgent security process or system migration. The attackers especially prefer contacting victims through personal phones, where employees have fewer enterprise monitoring protections and are more easily pulled into the immediate pressure of a live call.

Who is UNC6671?

UNC6671 is described as a data-extortion group focused on enterprise environments with large volumes of sensitive information, especially finance, hedge funds, private equity, and professional services. BleepingComputer says recent attacks against this target set have been linked to UNC6671 and show signs of association with BlackFile actors.

Unlike traditional ransomware campaigns, UNC6671 focuses on unauthorized access to cloud accounts and SaaS applications, then steals data to create pressure. This approach reduces the group's dependence on encrypting systems while still creating major legal, reputational, and breach-notification risks for victims.

Campaign progression

The first stage usually begins with a vishing call. The attacker claims to be internal support staff and gives a reason such as a security update, account migration, or urgent incident response. The goal is to make the victim believe they are completing a legitimate verification step for work.

After that, the victim may be led to a fake login flow or an intermediate authentication process. Reports indicate that the group may use adversary-in-the-middle techniques to collect credentials, multi-factor codes, or session tokens, opening the way into Microsoft 365, Okta, and other critical SaaS platforms.

Once access is obtained, UNC6671 searches for high-value data in email, document repositories, customer management applications, and collaboration systems. In the financial sector, this data can include transaction information, customer lists, investor records, legal exchanges, or internal documents used in negotiations.

Why personal phones become a weak point

Personal phones often sit outside the full control scope of the enterprise. Employees may receive calls, read messages, or open links without passing through the same filtering, logging, and alerting layers as managed devices. This is the gap UNC6671 exploits to build trust quickly and reduce the chance of early detection.

The social factor is also critical. A real human voice, an urgent script, and enough contextual information can persuade victims to overlook warning signs. In fast-moving organizations such as investment funds or professional services firms, constant work pressure makes the line between genuine support and fraud even blurrier.

Implications for Enterprises

The first risk is loss of control over data in SaaS platforms. One compromised account can open a chain of access to email, shared folders, financial applications, customer management systems, and legal documents. If attackers control session tokens, simply changing the password may not be enough to cut off all access.

The second risk is data-based extortion. In incidents of this type, attackers may not need to deploy ransomware at scale. Proving that they have obtained sensitive data can be enough to create pressure around reputation, compliance obligations, and customer relationships.

The third risk is erosion of trust in internal support processes. When attackers can imitate IT support scripts, employees may become uncertain about legitimate requests. Businesses therefore need to redesign how support requests are verified, without relying only on voice, caller ID, or a feeling of familiarity.

Defensive Lessons

Organizations should treat vishing as part of the formal threat model, especially when employees commonly use personal phones for work. IT support workflows need clear reverse-verification channels, such as employees calling back a published internal number, checking a ticket in the official system, or confirming through a device-management channel.

Technically, businesses need to monitor unusual SaaS logins, limit long-lived sessions, revoke tokens when compromise is suspected, apply phishing-resistant authentication such as FIDO2 security keys, and tightly control enrollment of new devices or authentication methods. Alerts for residential proxy logins, rapid location changes, and high-volume access to email and document stores should receive priority investigation.

For end users, the key rule is not to perform login requests, scan codes, install tools, or share authentication codes just because of an urgent phone call. Any request involving accounts, MFA, or system migration should be verified through an official channel before taking action.

Conclusion

The UNC6671 profile shows that data-extortion campaigns are shifting strongly toward identity and SaaS layers. When enterprise data lives in email, cloud applications, and collaboration tools, a successful vishing call can create consequences comparable to a serious technical vulnerability. Effective defense therefore requires identity controls, session monitoring, verified support workflows, and employee training based on realistic scenarios.

VNCyberS compiled from The Hacker News and BleepingComputer

Contact Us

Email: [email protected]
Phone: +84 903260277