UNC6671 Rebrands as REDACT, Expands Multi-Brand Vishing Extortion
The threat actor UNC6671, formerly known as BlackFile, has rebranded to REDACT and is actively diversifying its extortion operations under multiple aliases, targeting financial services and enterprise cloud environments with multi-brand vishing tactics.

Google Threat Intelligence Group (GTIG) continues to track the threat actor UNC6671, which remains active in data theft extortion operations despite the alleged retirement of its BlackFile brand in May 2026. Analysis of telemetry and infrastructure reveals that UNC6671 has not disbanded but has instead diversified its operations across several distinct extortion fronts, including REDACT, Pink, Helix, and Falcon. This strategic rebranding and diversification allow the group to maintain operational tempo and potentially evade detection.
The group's modus operandi consistently involves voice phishing (vishing) to target enterprise employees. Attackers pose as IT helpdesk staff, claiming to facilitate urgent security migrations. Notably, these calls are often directed at employees' personal mobile devices, luring them to spoofed login portals. These portals are designed to intercept credentials and multi-factor authentication (MFA) tokens through Adversary-in-the-Middle (AiTM) infrastructure. Once session persistence is achieved, the actors deploy automated scripts to exfiltrate data from cloud environments, specifically targeting platforms like Microsoft 365 and Okta.
While the initial access and post-compromise tactics, techniques, and procedures (TTPs) employed by UNC6671 have remained remarkably consistent across intrusions—leveraging vishing, AiTM credential harvesting, and SaaS data theft—the extortion messaging and data leak sites (DLS) have varied. Public statements from the group cited an affiliate breakaway as the reason for the initial rebrand to Redact. However, subsequent overlaps in phishing templates, victimology, and shared infrastructure conduits suggest a common set of threat actors are behind these various brands.
On June 27, 2026, the operators behind the Redact brand published a statement on their new DLS, detailing their alleged rebrand from BlackFile. They claimed that the original BlackFile brand had been compromised and hijacked by a former affiliate who operated an unauthorized, lookalike DLS and conducted unsanctioned extortion campaigns. According to Redact, this rogue affiliate intentionally orchestrated the "shutdown" of the BlackFile brand to create confusion among threat intelligence analysts and cyber insurance negotiators, thereby damaging the brand's reputation. Redact asserted that their rebranding was solely to distance themselves from this rogue activity and introduced a single verified Tox ID and PGP key for authentication.
Analysis of UNC6671's infrastructure reveals a shared ecosystem connecting these various phishing operations. The threat actors reuse generic root domains, often masquerading as passkey-related services, and append victim-specific subdomains to facilitate targeted vishing campaigns. This consistent digital footprint has exposed overlaps in victim targeting across multiple extortion brands, supporting the assessment that a common group of actors is affiliated with BlackFile, Redact, Pink, Helix, and Falcon. While other scenarios like splintered affiliates or shared Phishing-as-a-Service infrastructure are plausible, the evidence points to a unified operational base.
Specific examples highlight this shared infrastructure. The root domain passkeyhelpdesk[.]com was used to target organizations extorted under both the Falcon and Helix brands. Similarly, domains like portalpasskey[.]com and addssopasskey[.]com, used by Falcon, hosted intermediate targets that bridged directly into Helix infrastructure. The Pink brand utilized domains such as passkeyms[.]com and mysecurepasskey[.]com as intermediate bridges to infrastructure focused on passkeydeploy[.]com, which was also used to target BlackFile victims. This intricate web of shared domains and intermediate targets demonstrates a deliberate strategy to consolidate resources and potentially monetize compromised data across multiple fronts.
UNC6671's recent targeting has expanded to include financial services, private equity, and professional services firms. This shift in focus, combined with their sophisticated vishing and AiTM techniques, poses a significant threat to organizations in these sectors. The group's ability to operate under multiple aliases and leverage shared infrastructure makes them a persistent and adaptable adversary. Organizations are advised to implement robust security measures, including enhanced employee training on phishing and vishing, strict MFA policies, and continuous monitoring of cloud environments for suspicious activity.
Google Threat Intelligence Group (GTIG) analysis reveals that the group's public statement about an affiliate hijack being the reason for the BlackFile rebrand to Redact may be a cover. Overlaps in phishing templates, victimology, and shared infrastructure strongly suggest that associated actors are actively monetizing their operations under multiple extortion brands, including Pink, Helix, and Falcon, rather than a genuine affiliate breakaway. This indicates a coordinated effort to compartmentalize operations and obscure the true scale of their activities.
The threat group UNC6671, previously known as BlackFile, has expanded its operations under several new brand names including Redact, Pink, Helix, and Falcon. This financially motivated group has reportedly generated millions through its vishing-based extortion schemes, with the rebranding likely an effort to evade detection and continue its malicious activities.
This new report from Google Threat Intelligence Group and Mandiant details UNC6671's continued reliance on vishing attacks, specifically noting that threat actors often contact employees via their personal mobile devices. The report also provides a timeline of the group's various brand rebrandings and operational shifts, including the emergence of the Redact, Pink, Helix, and Falcon extortion brands, and highlights the group's diversification across multiple extortion brands as a tactic to monetize operations and frustrate tracking efforts.
The financially motivated extortion group, previously known as BlackFile, has expanded its operations under new aliases including Redact, Pink, Helix, and FalconData, according to Google's threat intelligence. These rebranded entities continue to target the financial services sector with sophisticated vishing and credential harvesting tactics, demonstrating a persistent threat despite the group's earlier declared retirement.
Uber Freight has confirmed it is investigating a data security incident where the Helix extortion group claims to have stolen nearly one million files. The group, linked to the UNC6671 cluster which has previously operated under the BlackFile name, reportedly uses vishing and device code phishing to gain access to cloud services and identity infrastructure. While Uber Freight states operations are unaffected and systems remain secure, the investigation is ongoing and the authenticity of the exfiltrated data has not been confirmed.