UNC6671 Targets Personal Phones to Steal Microsoft 365 and Okta Access

UNC6671 vishing campaign targets personal phones to steal Microsoft 365 and Okta access, bypassing MFA defenses.

UNC6671 Targets Personal Phones to Steal Microsoft 365 and Okta Access
Cloud Security

Illustrative image generated with AI

Targeted vishing against employees of financial organizations

A vishing campaign attributed to UNC6671 is targeting financial organizations, private equity firms, and professional services companies. The activity was detected on August 7, 2026, and has already affected dozens of organizations across North America, Australia, and the United Kingdom.

The operators call employees on their personal mobile numbers, often spoofing the caller ID to make it appear to be the company help desk. They pose as IT support staff and claim that mandatory security migrations must be completed urgently.

The call directs the victim to a fake login portal. The goal is not to exploit a vulnerability in Microsoft, Okta, or another vendor, but to persuade the user to surrender their authentication information.

Credential theft goes beyond passwords and bypasses MFA defenses

The portals use adversary-in-the-middle (AitM) infrastructure capable of intercepting credentials, MFA tokens, and already-authenticated sessions. This allows attackers to operate even when the account is protected by multifactor authentication.

Once they gain access to the identity provider, the attackers can reach multiple connected SaaS services without compromising each application individually. Targeted environments include:

  • Microsoft 365;
  • Okta;
  • Microsoft Entra ID.

The operators can also remove previously registered MFA devices and add devices under their own control. The compromise can therefore become persistent, making account recovery more difficult.

Automated Python and PowerShell scripts have also been observed collecting and exfiltrating data from cloud environments and SaaS applications.

UNC6671 and its associated extortion brands

Google Threat Intelligence Group and Mandiant identify the collective as UNC6671. CrowdStrike tracks it as part of the broader group known as Cordial Spider.

The group has been linked to the Redact, Pink, Helix, and Falcon extortion brands. BlackFile, also identified as CL-CRI-1116, is believed to be the name used previously. Pink is also known as CL-CRI-1147, while Falcon is known as CL-CRI-1182.

Google first documented UNC6671 in January 2026, linking it to techniques traditionally attributed to ShinyHunters, also known as Bling Libra. Available assessments indicate that the two groups operate independently.

The main changes among the brands occurred as follows:

  • on February 6, 2026, BlackFile’s data-leak site appeared;
  • in late April 2026, the site went offline;
  • on May 11, 2026, it briefly returned online to announce the brand’s closure;
  • on May 19, 2026, Redact announced that BlackFile operations had ended;
  • on May 31, 2026, Pink’s data-leak site appeared;
  • on June 27, 2026, Redact accused a former associate of hijacking the originalFile brand and conducting unauthorized extortion.

SOCRadar classified Pink’s activity as Big Game Hunting, a model that selects high-value targets and aims to quickly extract data before extorting the victim.

Observed domains and infrastructure

Pink uses customized phishing kits for Okta and Entra ID. Conditional access systems attempt to evade sandboxes and researchers, while the infrastructure has been hosted through Cloudflare and DDoS-Guard.

Tucows and Nicenic appear to have been used to register the domains. Credential-harvesting panels are hosted on generic domains associated with passkeys, MFA, or SSO, with subdomains created for individual victims.

Reported indicators include:

passkeyhelpdesk[.]com
setupsso[.]com
idokta[.]com

Some domains were reportedly used simultaneously against two different victims, claimed respectively by Falcon and Helix.

How to reduce the risk

Organizations should deploy phishing-resistant MFA for accounts that access SaaS platforms and identity systems. Help desk calls should be verified through independent channels, particularly when they reach personal numbers or demand urgent migrations.

Organizations should also monitor the identity provider for:

  • registration of new MFA devices;
  • removal of previously authorized devices;
  • anomalous logins and sessions;
  • changes to SSO and account configurations;
  • unusual activity in Microsoft 365, Okta, and Entra ID.

Monitoring should also cover domains and subdomains referencing passkeys, MFA, and SSO, including the indicators already observed. Unauthorized access to the IdP can propagate to numerous connected SaaS services, even without further attacks against individual applications.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →