logo

'Several dozen' high-value corporations hit by new extortion crew in helpdesk phishing spree

ID: ff1fcd62-9cbe-5e85-b3cb-06591f688175

STIX ID: report--ff1fcd62-9cbe-5e85-b3cb-06591f688175

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

UNC6783 is a financially motivated extortion crew targeting dozens of high-value corporations by compromising BPOs and helpdesk staff through social engineering and phishing (including spoofed Okta pages). The group uses a custom phishing kit to bypass MFA, steals credentials and data, deploys remote-access malware, and sends ransom notes via ProtonMail; an alleged Adobe breach claims large-scale data theft of support tickets and employee records.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.