Picture this: one of your staff gets a call on their personal cell phone — not their work line — from someone who sounds exactly like your IT help desk. Caller ID even matches. The “technician” says a mandatory security migration requires them to re-enroll their multi-factor authentication right now, or their account gets locked. Five minutes later, that employee has typed their credentials and MFA code into a page that looks pixel-perfect like your company’s login screen. Game over — not because your firewall failed, but because a phone call did what no exploit could.
That scenario isn’t hypothetical. It’s the exact playbook a data-extortion crew tracked as UNC6671 has been running against financial services firms, private equity shops, and professional services companies throughout the summer of 2026 — and it’s a pattern every Microsoft 365 tenant owner should understand, because the group’s targets and toolkit map almost perfectly onto what a lot of small and mid-sized firms run day to day.
What’s Actually Happening
UNC6671 isn’t a new group discovering a clever trick — it’s a well-resourced operation that has been steadily refining a single technique: voice phishing, or “vishing,” aimed at real employees on their personal mobile numbers. Security researchers at Google’s Threat Intelligence Group and Mandiant have tracked this activity since earlier in 2026 under an extortion brand called BlackFile, which publicly announced it was shutting down in May. Instead of disappearing, the operation appears to have splintered — or rebranded — into several new extortion labels (Redact, Pink, Helix, and Falcon among them), all while reusing the same phishing infrastructure, the same call scripts, and the same technical playbook.
That consistency is the real story. Regardless of which name shows up on a ransom note, the underlying attack hasn’t changed: call an employee, impersonate IT, harvest credentials and MFA tokens in real time, then quietly pull data out of Microsoft 365 or Okta using scripted, automated tools.
Between January and May 2026 alone, researchers traced roughly $10.7 million in ransom payments tied to this group’s wallets, with initial demands often starting between $1 million and $3 million and settling closer to $750,000 after negotiation. This isn’t a smash-and-grab operation. It’s a business.
How the Attack Actually Works
- The setup. Operators research a target company on LinkedIn, identifying IT and identity-management staff by title, then register a lookalike domain — something like
companyname-passkey.comoraddssopasskey.com— often within hours of choosing a victim. - The call. An employee’s personal mobile number rings — not their desk phone. The caller claims to be IT, sometimes spoofing the company’s actual help desk number to add legitimacy, and insists on an urgent, mandatory action: re-enrolling a passkey, updating MFA, or completing a “security migration.”
- The trap. The employee is walked through entering their credentials and MFA code into a spoofed login portal. Behind that page sits an Adversary-in-the-Middle (AiTM) proxy — meaning the attacker isn’t just stealing a password, they’re intercepting the live authenticated session in real time. This defeats push notifications, SMS codes, and app-based one-time codes equally well, because none of those methods verify which domain the user is actually authenticating to.
- The quiet part. Once the session is hijacked, operators use it to establish persistence — sometimes resetting passwords on other connected apps and then deleting the resulting security alerts and confirmation emails so nobody notices. From there, automated Python and PowerShell scripts systematically pull data out of SharePoint, OneDrive, Exchange Online, and other connected SaaS platforms.
- The extortion. Stolen data ends up listed on a leak site under whichever brand name the operators are using that month, with a ransom demand attached.
Nothing in this chain requires a software vulnerability. It requires one distracted or well-intentioned employee and thirty seconds of hesitation before they double-check who’s actually calling.
Why This Matters More for Smaller Microsoft 365 Tenants
It’s tempting to read “financial services and private equity” and assume this is someone else’s problem. It isn’t, for a few practical reasons:
- A caller claiming to be “IT” or naming your MSP by name is far more convincing at a smaller company, where employees are used to a familiar, informal help desk relationship rather than a large, anonymous corporate IT department.
- Most SMB Microsoft 365 tenants still lean on SMS or push-based MFA, which this attack is specifically built to defeat. Traditional MFA slows down opportunistic attackers — it does almost nothing against a live AiTM proxy.
- A single compromised admin or finance account in a small tenant often has outsized reach — fewer segmented permissions, fewer layers between “help desk password reset” and “access to every client file in SharePoint.”
- Attackers are actively expanding beyond their original targets. The domain-registration pattern researchers tracked shows a clear month-over-month broadening — manufacturing and healthcare in the spring, technology and hospitality by early summer, financial and legal services by July. The targeting keeps moving toward whoever holds sensitive data, and the tempo has been accelerating, not slowing.
What To Do This Week
You don’t need an enterprise security team to meaningfully close this gap in a Microsoft 365 / Entra ID environment. In rough priority order:
- Move off SMS and push MFA where it matters most. Enable phishing-resistant authentication — Windows Hello for Business, FIDO2 security keys, or Microsoft Authenticator passkeys — at minimum for admins, finance, and anyone with access to client data. These methods cryptographically bind to the real domain, so a lookalike site simply can’t complete the login.
- Tighten Conditional Access in Entra ID. Require managed or compliant devices for sign-in, shrink session lifetimes so stolen tokens expire faster, and add step-up authentication for sensitive actions like mailbox rule changes or SharePoint bulk downloads.
- Get every business app behind single sign-on. Apps outside your SSO umbrella are blind spots — they don’t inherit your Conditional Access policies or MFA requirements.
- Turn on real alerting for the quiet stuff. Watch for MFA re-enrollment events that immediately follow a failed sign-in, password resets on non-SSO apps, and unusual PowerShell or scripted access to SharePoint content — the exact fingerprints this group leaves behind.
- Brief your team on the actual pretext, not just “phishing” in the abstract. The specific lure here is a call to a personal phone about an urgent, mandatory MFA or passkey update. A five-minute conversation about that one scenario will do more than a generic annual security training video.
- Have a documented callback policy. Nobody — including real IT — should ever ask an employee to authenticate through a link read to them over the phone. Any “urgent” IT request should be verified by calling back through a known, internal number.
Where This Fits With US 365 Cloud Consulting
This is squarely the kind of exposure a Tenant Assessment is built to catch — reviewing your Entra ID Conditional Access policies, MFA methods, session controls, and admin permissions against exactly this style of attack, then closing the gaps without disrupting how your team works day to day. If you’re an MSP managing a handful of client tenants, this is also a good moment to have those same protections rolled out consistently across every environment you support, white-labeled under your own brand.
If you want a second set of eyes on whether your tenant would actually stand up to a call like the one described above, that’s a conversation worth having before an attacker forces it.
US 365 Cloud Consulting helps businesses and MSPs get more out of Microsoft 365 — securely. Questions? Reach us at info@us365cloudconsulting.com or 603-759-8721.
This post is provided for informational purposes based on publicly reported threat research and does not constitute a security guarantee or formal incident response guidance. If you believe your organization has been targeted or compromised, engage your incident response provider immediately.

Leave a Reply