UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
thehackernews.com Aug 8, 2026

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

AI-summarised brief · reviewed before publication

A cyber‑extortion group known as UNC6671 has intensified vishing attacks on financial, private equity, and professional services firms, targeting employees through personal mobile phones. The attackers pose as IT help desk staff to prompt users into spoofed login portals, where adversary‑in‑the‑middle (AitM) infrastructure captures credentials and MFA tokens. The stolen data enables persistent access and automated scripts that exfiltrate information from cloud services such as Microsoft 365 and Okta. UNC6671 operates under multiple extortion brands, including Redact, Pink, Helix, and Falcon, and has shifted its focus across sectors since January 2026.

💡 Why It Matters

  • · The campaign exposes how social engineering can bypass even MFA, forcing organizations to adopt phishing‑resistant authentication.
  • · It underscores the growing sophistication of threat actors who leverage personal devices to compromise enterprise identities.