Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
UNC6671 Exploits Microsoft 365 Through Phishing Attacks

UNC6671 Exploits Microsoft 365 Through Phishing Attacks

Posted on August 7, 2026 By CWS

UNC6671, a cyber group, has been orchestrating a series of sophisticated data theft operations targeting Microsoft 365 users. Their modus operandi begins with a deceptive phone call, where the group impersonates IT support, urging employees to engage in a supposed security upgrade. This initial contact, followed by a fraudulent login page, serves as the entry point for their malicious activities.

Deceptive Tactics and Security Breaches

The urgency created by these calls often prevents employees from validating the authenticity of the request. Unlike traditional attacks, this campaign does not require password cracking. Instead, it captures login credentials and active authentication tokens, allowing attackers to impersonate employees and access sensitive data within Microsoft 365 or Okta environments.

Google Cloud analysts have uncovered this ongoing data theft and extortion scheme. The attackers, although reportedly retiring their BlackFile brand, continue to operate under different aliases such as Redact, Pink, Helix, and Falcon. The repercussions of these breaches go beyond compromised emails, as sensitive information stolen can be used for extortion.

Targeted Industries and Attack Methodology

Recently, UNC6671 has focused on financial services, private equity, and professional services sectors, where confidential deal and litigation data hold significant value. The group initiates their operations via voice phishing, or ‘vishing,’ using personal mobile numbers to impersonate IT helpdesks and request multi-factor authentication updates.

Victims are directed to fake enrollment portals, mimicking legitimate login pages. This adversary-in-the-middle strategy captures passwords and tokens, allowing attackers to hijack sessions without alerting the user. Automated scripts are then employed to extract data from cloud services, utilizing residential proxies to mask the activity as normal user traffic.

Preventive Measures and Defensive Strategies

Organizations should implement robust verification procedures and employ phishing-resistant authentication methods. Security teams are advised to reduce session lifetimes, enforce stringent access checks for sensitive resources, and limit authentication to trusted devices and networks. Monitoring identity-provider and Microsoft 365 audit logs can reveal signs of compromised sessions, such as unusual multi-factor enrollments or high-volume data access.

Google Cloud research highlights the shared infrastructure used by multiple extortion groups, suggesting a coordinated effort or shared service model. Frequent domain changes reinforce the illusion of routine security tasks, complicating defenses. Companies should equip employees to identify and report suspicious helpdesk requests through official channels.

In summary, UNC6671’s tactics underscore the importance of comprehensive security frameworks. Combining employee training, advanced authentication controls, and behavioral monitoring can thwart these phishing campaigns before they escalate into data theft and extortion.

Cyber Security News Tags:corporate data, Cybersecurity, data theft, Extortion, Google Cloud, IT security, Microsoft 365, Phishing, session hijacking, UNC6671, Vishing

Post navigation

Previous Post: Vishing Group UNC6671 Restructures After Millions in Extortion

Related Posts

CISA Warns of Critical SunPower Device Vulnerability Let Attackers Gain Full Device Access CISA Warns of Critical SunPower Device Vulnerability Let Attackers Gain Full Device Access Cyber Security News
vLLM Vulnerability Enables Remote Code Execution Via Malicious Payloads vLLM Vulnerability Enables Remote Code Execution Via Malicious Payloads Cyber Security News
Infostealer Logs Drive Major Cloud Data Breaches Infostealer Logs Drive Major Cloud Data Breaches Cyber Security News
Russia’s Use of Cellebrite to Access Activist’s iPhone Russia’s Use of Cellebrite to Access Activist’s iPhone Cyber Security News
Supply Chain Attack Targets art-template npm Package Supply Chain Attack Targets art-template npm Package Cyber Security News
Outdated PHP in WordPress Poses Cybersecurity Threat Outdated PHP in WordPress Poses Cybersecurity Threat Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • UNC6671 Exploits Microsoft 365 Through Phishing Attacks
  • Vishing Group UNC6671 Restructures After Millions in Extortion
  • AitM Phishing Targets Microsoft 365 for Payroll Data
  • CHAINDROP Malware Targets Over 400 npm Packages
  • Bendix Brake Controller Recall Exposes Hidden Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • UNC6671 Exploits Microsoft 365 Through Phishing Attacks
  • Vishing Group UNC6671 Restructures After Millions in Extortion
  • AitM Phishing Targets Microsoft 365 for Payroll Data
  • CHAINDROP Malware Targets Over 400 npm Packages
  • Bendix Brake Controller Recall Exposes Hidden Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark