logo

Welcome to BlackFile: Inside a Vishing Extortion Operation

ID: 07b73e1c-3344-5ae9-ba08-89daf96c209e

STIX ID: report--07b73e1c-3344-5ae9-ba08-89daf96c209e

Feed Name: DataBreaches.Net

Threat Score
78/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: Dissent

...
...

**Google Threat Intelligence Group (GTIG)** reports that UNC6671, operating under the “**BlackFile**” brand, runs an active extortion campaign using voice phishing (vishing) and adversary-in-the-middle (AiTM) SSO compromises to bypass MFA, target Microsoft 365 and Okta environments, programmatically exfiltrate sensitive corporate data, and pressure victims via a dedicated data leak site; the group has targeted dozens of organizations across North America, Australia, and the UK, and GTIG emphasizes moving toward phishing-resistant MFA and other identity-centric defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.