logo

Inside UNC6671’s “BlackFile” Cloud Extortion Campaigns

ID: 757995a4-b4e9-5a33-8ca7-2d5ed1b2f58c

STIX ID: report--757995a4-b4e9-5a33-8ca7-2d5ed1b2f58c

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Ddos

...
...

UNC6671, also known as BlackFile, is an identity-focused extortion group that used vishing and adversary-in-the-middle (AiTM) proxy infrastructure to intercept credentials and active session cookies, bypass MFA, and exfiltrate sensitive data from Microsoft 365 and Okta environments across dozens of organizations in North America, Australia, and the UK; the group published stolen data on a data-leak site for extortion before announcing a shutdown of the BlackFile brand, though its methods remain a significant blueprint for future attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.