BlackFile Cybercrime Group Escalates Attacks on Financial Sector with Sophisticated Social Engineering
The BlackFile cybercrime group, also known as UNC6671, is actively targeting financial institutions and other large organizations with voice-phishing and social engineering tactics, employing multiple brands to conduct 'big-game hunting' extortion operations.

The BlackFile cybercrime group, identified by Google Threat Intelligence Group as UNC6671 and broadly associated with the larger 'The Com' threat cluster, continues its aggressive campaign against financial companies, private equity firms, law firms, and financial rating agencies. Researchers have observed the group actively pursuing new victims, demonstrating a persistent and evolving threat to high-value targets.
Operating under a multi-brand strategy, BlackFile has launched its extortion operations across four distinct brands: Redact, Pink, Helix, and Falcon. This approach allows the group to diversify its attack vectors and potentially evade detection by using shared infrastructure across these different personas. Google reported that several organizations received new extortion demands from the Redact brand in the past week alone, underscoring the group's ongoing activity.
BlackFile's modus operandi involves sophisticated voice-phishing and social engineering attacks, where threat actors impersonate IT support personnel to gain initial access. This tactic, while not novel, has proven highly effective for the group. They engage in "big-game hunting," specifically targeting large organizations with substantial extortion demands, often initiating requests at $3 million. While payments have typically been negotiated down to less than $1 million, the scale of their operations is significant.
Since the beginning of the year, BlackFile has compromised over two dozen organizations, averaging approximately 1.5 new victims daily. Their targets span a wide array of industries, including healthcare, technology, transportation, logistics, wholesale, retail, and hospitality, indicating a broad operational scope. Mandiant incident responders have been engaged by more than two dozen organizations successfully compromised by the threat group since January, with new victims in the financial sector seeking assistance as recently as earlier this month.
Researchers at Flashpoint have observed malicious infrastructure targeting prominent firms such as Blackstone, Bain Capital, Moody's, CME, and Apollo, although it remains unclear if these specific entities were compromised. The group's tactics extend beyond data exfiltration and extortion, with some recent victims subjected to threatening messages and even swatting incidents, a tactic associated with subsets of 'The Com'.
At the core of BlackFile's operations are hundreds of callers, often recruited individuals paid a small fee or offered goodwill within the group, who execute the voice-phishing calls. Austin Larsen, principal threat analyst at GTIG, estimates that fewer than a dozen core operators manage the various brands under the BlackFile umbrella, linking them all back to the same threat cluster through shared infrastructure. This centralized control allows for coordinated and efficient operations.
The continued success of BlackFile highlights the enduring effectiveness of exploiting human weaknesses in cybersecurity. Despite the availability of advanced security technologies, the group's reliance on social engineering and voice-phishing demonstrates that human-centric attacks remain a potent threat vector for cybercrime groups seeking to compromise organizations of all sizes and sectors.
BlackFile's steady pace of victim acquisition and its multi-brand strategy present a significant and ongoing challenge for cybersecurity professionals. The group's ability to consistently target and compromise large organizations, coupled with its escalation tactics, positions it as a major threat actor in the current cybercrime landscape.