← Back to Crime & Security

UNC6671 Extortion Group Targets Global Financial Sector via Voice Phishing Campaign

Crime & SecurityAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

A sophisticated cyber-extortion group known as UNC6671 has launched a coordinated wave of attacks against hedge funds, private equity firms, and other financial organizations worldwide. The campaign, identified on Aug. 6, utilizes voice phishing tactics to compromise helpdesk systems and steal sensitive data.

The attack vector relies heavily on social engineering directed at IT support personnel. Threat actors pose as legitimate employees seeking urgent assistance with password resets or account access issues. By manipulating these helpdesk staff members into bypassing standard security protocols, the group gains unauthorized entry into corporate networks. Once inside, attackers exploit cloud infrastructure to exfiltrate proprietary financial data and deploy ransomware.

Security analysts have linked this latest offensive to a broader campaign previously designated as BlackFile. The operation marks an escalation in tactics for UNC6671, shifting from traditional email-based phishing to real-time voice interactions that are more difficult to detect with automated filters. Financial institutions across North America, Europe, and Asia have reported incidents involving unauthorized access attempts and data theft demands.

The primary objective of the campaign is financial extortion. After securing cloud access, attackers encrypt critical systems or threaten to release stolen intellectual property unless a ransom is paid in cryptocurrency. The targeted organizations include major asset managers and investment vehicles holding billions in assets. Unlike previous attacks that focused on individual endpoints, this operation aims for broad network penetration through trusted administrative channels.

Industry experts note the increasing sophistication of the voice phishing scripts used by UNC6671. Callers utilize deepfake audio technology to mimic known executives or IT administrators, adding a layer of credibility to their requests. This approach has proven effective in bypassing multi-factor authentication measures that typically rely on user verification rather than system-level checks.

Financial regulators and cybersecurity firms are currently working with affected organizations to contain the breaches and restore secure access protocols. Several high-profile victims have declined to comment publicly while internal investigations continue. The global nature of the attacks suggests a well-resourced operation capable of targeting multiple time zones simultaneously.

Questions remain regarding the full scope of data compromised during these initial waves. While some firms have successfully isolated infected systems, others report ongoing unauthorized access attempts. Authorities are investigating whether UNC6671 has established persistent backdoors within cloud environments that could allow for future re-entry even after immediate threats are neutralized. As the campaign evolves, financial institutions face an urgent need to update helpdesk verification procedures and implement stricter voice authentication protocols.

Discussion

0 / 2000