logo

New BlackFile extortion group linked to surge of vishing attacks

ID: c21beb12-8127-5ad5-b801-e4cedd84cab5

STIX ID: report--c21beb12-8127-5ad5-b801-e4cedd84cab5

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Sergiu Gatlan

...
...

BlackFile (also tracked as CL-CRI-1116/UNC6671/Cordial Spider) is a financially motivated criminal group conducting vishing campaigns since February 2026 to steal employee credentials, register attacker devices to bypass MFA, and exfiltrate sensitive files from Salesforce and SharePoint using standard APIs; stolen data is posted to a dark web leak site and victims are extorted with seven-figure ransom demands, with retail and hospitality organizations identified as primary targets and RH-ISAC/Unit 42 providing mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.