Despite a very public “retirement” announcement in May 2026, the threat cluster tracked as UNC6671 hasn’t gone anywhere it’s simply multiplied.
Google Threat Intelligence Group (GTIG) now links the group to at least five separate data-leak-site brands: BlackFile, Redact, Pink, Helix, and Falcon, all running the same vishing-driven playbook against financial services, private equity, law firms, and enterprise cloud environments.
When BlackFile’s leak site went dark on May 11, 2026, cyber insurers and threat analysts treated it as a shutdown. GTIG’s telemetry tells a different story: ransom payments to BlackFile’s Bitcoin wallets continued uninterrupted through the “shutdown,” including major cashout events in late April and early May.
UNC6671 Rebrands
On June 27, 2026, the newly minted Redact brand published a statement blaming a rogue affiliate for hijacking BlackFile’s identity while denying that any pressure from rival groups drove the rebrand.
But infrastructure overlaps tell a more coordinated story: phishing panels, victim targeting, and root-domain reuse consistently bridge Redact, Pink, Helix, and Falcon back to the same operational core.

UNC6671’s tradecraft hasn’t changed; only its packaging has. The group hosts credential-harvesting panels on generic root domains mimicking passkey and SSO enrollment (think passkeyhelpdesk[.]com or addssopasskey[.]com), then appends victim-specific subdomains for each vishing target.
GTIG found identical phishing templates deployed simultaneously across domains tied to different DLS brands; for example, passkeyhelpdesk[.]com targeted victims later claimed by both Falcon and Helix.
That kind of infrastructure convergence, paired with intermediary domains that bridge one brand’s targets into another’s clusters, is hard to explain as a coincidence.
UNC6671’s victim selection has sharpened over time. Between April and May 2026, campaigns cast a wide net across manufacturing, real estate, healthcare, and insurance.
By June, the focus shifted to tech, transportation, and hospitality firms that hold valuable IP and source code. By July, the group had narrowed in on financial services and legal sectors private equity firms, law firms, and rating agencies organizations sitting on sensitive M&A and litigation data that maximizes extortion leverage.
Operational tempo has also accelerated, from one new domain roughly every 2.2 days in spring to one every 1.6 days by summer, with a burst of seven domains provisioned in a single 72-hour window in late July.

Vishing callers now spoof legitimate helpdesk numbers to add credibility to their fake “passkey enrollment” mandates, still reaching employees on personal phones to bypass corporate controls.
Post-compromise, operators have escalated evasion by using hijacked email accounts to reset passwords on non-SSO apps, then systematically deleting the resulting security notifications and MFA change alerts to remain hidden longer.
GTIG traced 18 BlackFile wallets receiving 141.65 BTC (~$10.69 million) between January and May 2026. Initial demands often start at $1–3 million, but negotiations typically cut that by 50–75%, with over half of tracked cases settling near $750,000.
GTIG’s core recommendation is unambiguous: deploy phishing-resistant, FIDO2-based authentication everywhere, since WebAuthn’s origin-binding neutralizes lookalike domains entirely.
Pair that with tighter session controls, trusted-network restrictions, managed-device requirements, and SOC monitoring tuned to catch scripted SaaS exfiltration and abandoned MFA-enrollment attempts the fingerprints UNC6671 leaves behind regardless of which brand name it’s wearing that week.