logo

BlackFile Group Targets Retail and Hospitality with Vishing Attacks

ID: 0019bac9-5a06-5d65-bbfc-d0f91acfd733

STIX ID: report--0019bac9-5a06-5d65-bbfc-d0f91acfd733

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

...
...

Palo Alto Networks Unit 42 and RH-ISAC published a report on April 23 detailing BlackFile (activity cluster CL-CRI-1116), a financially motivated extortion group targeting retail and hospitality that uses vishing and credential phishing to register devices and bypass MFA, then abuses legitimate APIs and SSO sessions to scrape and exfiltrate sensitive data from SharePoint and Salesforce before demanding large ransoms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.