logo

Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks

ID: 7d396776-3209-530b-8e85-08fdf4f748a2

STIX ID: report--7d396776-3209-530b-8e85-08fdf4f748a2

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers warn that two cybercrime clusters—Cordial Spider (aka BlackFile/UNC6671) and Snarky Spider (aka UNC6661)—are conducting rapid, high-impact extortion and data theft operations that operate primarily inside trusted SaaS environments. Using vishing to lure victims to SSO-themed adversary-in-the-middle pages, the actors capture credentials and MFA codes, register new devices to bypass MFA, delete notification emails via inbox rules, and pivot through compromised identity providers to rapidly exfiltrate sensitive files from Google Workspace, HubSpot, Microsoft SharePoint, and Salesforce, creating significant detection challenges for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.