A spoofed IT number on a personal cell phone was enough to put multi-billion-dollar hedge fund SSO sessions in attacker hands. According to BleepingComputer, operators tracked as UNC6671 called employees at firms including Point72, Millennium, Two Sigma, Citadel, Blackstone, KKR, and Apollo, claimed an urgent passkey or MFA update, and steered them to company-branded reverse-proxy sites that harvested passwords, live MFA codes or push approvals, and session cookies for Microsoft 365 and Okta. Google Threat Intelligence Group later tied the wave to a multi-brand extortion network that had already pulled more than $10.6 million in Bitcoin ransoms earlier in 2026.
How spoofed helpdesk calls reached personal mobiles
The first move was not a clever email. It was a phone call that looked like internal IT.
According to reporting that cites Google Threat Intelligence Group (GTIG) principal threat analyst Austin Larsen, operators dialed employees on personal mobile numbers while spoofing corporate helpdesk or IT caller IDs. The pitch was urgency dressed as security hygiene: enroll a passkey, update MFA, finish a required identity change before access broke. That framing matters. It turned a security task into social pressure, and it moved the conversation off corporate email, managed endpoints, and monitored collaboration tools.
Personal-phone vishing sits outside the usual mail gateway and browser-isolation stack. There is no secure email gateway verdict on a ringing cell phone. There is no conditional access prompt until the victim already trusts the voice on the line and opens the link the caller dictates. Helpdesk culture makes that trust easy to abuse. Staff are trained to comply with IT when something sounds time-sensitive and official. Attackers borrowed that muscle memory.
GTIG assesses that a single core intrusion group is driving helpdesk vishing and cloud data theft across public extortion brands that include Redact, Pink, Helix, and Falcon, after earlier operations under the BlackFile name. Falcon publicly disputed shared-umbrella claims with Helix and Pink and said it operates only as a Redact affiliate. GTIG still tracks the intrusion infrastructure, domain patterns, and multi-brand extortion network as UNC6671, and it distinguishes that set from Scattered Spider (UNC3944) even while noting tactical similarities in helpdesk vishing and adversary-in-the-middle interception.
The sector shift is part of the story. BlackFile first appeared in February 2025 against retail and hospitality targets. In May 2026 the brand rebranded to Redact on its leak site. By July 2026, targeting had swung hard toward private equity, hedge funds, major law firms, and financial rating agencies. Mandiant has been assisting several dozen organizations compromised in the broader UNC6671 activity, per the same public reporting.
How company-branded AiTM sites captured live MFA
An adversary-in-the-middle attack is a reverse proxy that sits between the user and the real identity provider, copying passwords and second factors as the real login completes. That is the second half of the UNC6671 initial-access path.
Victims who accepted the vishing story were sent to lookalike, company-branded sites. Those pages did not need to break cryptography. They needed the user to type a password and satisfy a transferable second factor while the proxy watched. App OTP codes, SMS codes, and push approvals all travel as secrets or approvals the attacker can capture or relay in real time. Once the legitimate Microsoft 365 or Okta ceremony finished through the proxy, the attacker held usable proof of authentication and, critically, a path to register their own MFA device on the account.
That enrollment step is where a one-time interception becomes durable control. After live credential and MFA interception, operators added attacker-controlled authenticators. Later logins no longer depended on catching the victim mid-call. The account now accepted a factor the attacker owned. Session cookies and SSO tokens stolen after MFA then let them open Microsoft 365 or Okta dashboards without another challenge and replay access from their own infrastructure.
| Control in play | What UNC6671 did with it | Why it failed here |
|---|---|---|
| Helpdesk / IT trust | Spoofed caller ID, urgent MFA story | Voice channel sat outside email and EDR |
| App OTP, SMS, or push | Relayed codes or approvals live | Secrets and prompts are transferable |
| Passkey or MFA "update" task | Coached victims onto branded AiTM pages | Enrollment became the social hook |
| M365 / Okta SSO session | Replayed cookies into cloud apps | Bearer tokens needed no fresh login |
Point72 publicly reported an attack and said it found no evidence client data was stolen. Two Sigma reported a blocked attempt with no indication systems or data were affected. Millennium and Citadel declined comment. Exact firm-by-firm loss totals and full public IoC sets are not available in the open reporting, so treat named-firm impact as uneven and partly unconfirmed rather than a single shared dump story.
What stolen M365 and Okta sessions unlocked next
Once SSO tokens and session cookies were in hand, the blast radius was the federation graph, not a single mailbox.
Attackers used automated tooling against linked cloud services such as SharePoint, OneDrive, and Salesforce, pulling data useful for extortion. They also deleted security notifications and password-reset related mail to slow detection. That is classic post-authentication work. No second factor is sitting in front of a cookie the identity provider already issued. Shortening session lifetime only forces faster reuse. It does not unwind a token already copied off an AiTM path, and it does nothing if the attacker already enrolled a lasting factor during the same window.
Money followed the access. According to Austin Larsen of GTIG, between January and May 2026 the group’s wallets received more than $10.6 million USD in Bitcoin. Initial demands often reached about $3 million and routinely settled near $750,000 after negotiation. Those figures predate and surround the heavier Wall Street focus; they show a working extortion business, not a one-off publicity stunt.
SSO is the force multiplier. One good Microsoft 365 or Okta session becomes mail, files, CRM, and admin surfaces without a fresh interactive login at each app. Zero-trust language says never trust, always verify. Classic SSO auto-login does the opposite once a bearer token exists. In this campaign the token was not magic. It was the predictable output of a phishable login that a helpdesk-shaped phone call had already sold to the victim.
The mechanical failure is therefore front-loaded. Transferable passwords and OTP or push factors gave the proxy something to steal. Socially engineered enrollment gave the attackers a permanent second factor. Only after those credential-phase wins did session replay and cloud exfiltration look easy. Defenders who jump straight to "detect the cookie" skip the part of the chain that made the cookie available from a phone call and a fake login page.
BlackFile’s earlier retail and hospitality wave, and adjacent brand names such as Helix in other vishing-and-cloud-theft reporting, sit in the same GTIG multi-brand picture. They show campaign evolution and brand hopping more than a brand-new invention of helpdesk fraud. The finance-sector version simply aimed the same voice-plus-AiTM pattern at people whose cloud estates hold deal rooms, portfolio data, and partner correspondence.
If you want to skip the attack details and go straight to what can stop this, read the related article on mfa2point0.com: where hardened enrollment and device-bound authentication break UNC6671-style vishing and AiTM.
FAQ
How did UNC6671 get into hedge fund and PE Microsoft 365 or Okta accounts?
UNC6671 operators got in by calling employees on personal mobiles while spoofing corporate helpdesk numbers, then directing them to company-branded AiTM sites that captured passwords and live MFA codes or push approvals during real Microsoft 365 or Okta logins. After that interception they registered their own MFA devices and replayed stolen session cookies into SSO dashboards. The phone call created trust; the reverse proxy turned a normal workforce login into attacker-held credentials and tokens.
Did every named firm lose client data in the UNC6671 wave?
No public reporting confirms client or firm-wide data loss at every named organization in the UNC6671 Wall Street wave. Point72 reported an attack but said it found no evidence client data was stolen. Two Sigma reported a blocked attempt with no indication systems or data were affected. Millennium and Citadel declined comment. Mandiant has assisted several dozen compromised organizations across the broader activity, but exact victim counts and per-firm forensic totals remain unpublished.
Is UNC6671 the same as Scattered Spider?
GTIG does not treat UNC6671 as Scattered Spider. Austin Larsen told BleepingComputer that helpdesk vishing and adversary-in-the-middle interception resemble methods historically associated with Scattered Spider (UNC3944), yet GTIG tracks this infrastructure, domain registration pattern, and multi-brand extortion network separately as UNC6671. Falcon also disputed being under one umbrella with Helix or Pink while describing itself as a Redact affiliate.
Why didn't ordinary MFA stop the AiTM step?
Ordinary app OTP, SMS, and push MFA did not stop the AiTM step because those factors are transferable during a live proxied login. The UNC6671 sites presented company-branded pages, collected the password, and captured or relayed the second factor as the real IdP authenticated the session. Attackers then enrolled their own MFA devices, so later access no longer needed the original victim on the line. Only after authentication had already succeeded did stolen session cookies unlock cloud apps without another challenge.
What should IT managers assume about SSO after a vishing-guided login?
IT managers should assume a vishing-guided AiTM login can mint a full Microsoft 365 or Okta SSO session that fans out into SharePoint, OneDrive, Salesforce, and other integrated apps, and that attackers in this campaign also deleted security alerts to hide. Revoking sessions and killing refresh tokens is necessary containment after the fact, but the enabling failure was the helpdesk-shaped call plus phishable factors that let a remote proxy finish authentication and enroll new devices in the first place.