Find notable cyber news and cases, enriched with sources, timelines, and signals.

UNC6671 industrializes vishing credential theft with role-separated labor across extortion brands

Threat Actor Meta
First reported
Last updated
Happening score
H score 47
1 unique sources, 1 articles

Summary

Hide ▲

UNC6671 is industrializing vishing-driven credential theft with a role-separated labor model that improves scale and reduces insider risk across extortion brands. Its Work Panel splits callers, managers, and admins into different access tiers, turning recruited labor into interchangeable capture capacity. The structure makes credential relay, reconnaissance, and infrastructure control easier to operationalize at criminal-service scale.

Related Happenings

RecruitTrap recruitment-themed phishing campaign

Campaign
H score25 First: 14.08.2026 13:57 Last: 14.08.2026 13:57 Sources 1

About this happening: The RecruitTrap campaign used fake recruiter outreach and BitB login pages to steal Google and Facebook credentials and relay MFA prompts in real time. It span...

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
H score34 First: 07.08.2026 13:38 Last: 07.08.2026 13:38 Sources 1

About this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...

ShinyHunters social engineering campaign targeting employee SSO accounts

Campaign
H score77 First: 17.07.2026 23:45 Last: 17.07.2026 23:45 Sources 1

About this happening: The ShinyHunters extortion gang is running an ongoing social engineering campaign against employee Microsoft Entra, Okta, and Google SSO accounts, creating a path into...

Service desk social engineering defenses tighten identity verification for password resets and MFA changes

Defensive Guidance
H score17 First: 24.06.2026 17:02 Last: 24.06.2026 17:02 Sources 1

About this happening: Service desk identity verification is being tightened against social engineering attacks, reducing impersonation-driven account takeover and unauthorized access across cor...

UNC6692 email bombing and Microsoft Teams impersonation campaign

Campaign
H score32 First: 25.04.2026 18:07 Last: 25.04.2026 18:07 Sources 1

About this happening: UNC6692 is running a social-engineering campaign that uses email bombing and Microsoft Teams impersonation to push targets toward remote access and initial compromise....

Timeline

  1. 18.08.2026 19:58 2 articles · 3h ago

    UNC6671 runs a sustained AitM extortion operation across multiple brands

    Campaign Scope Update

    GuidePoint identifies UNC6671, also tracked as Cordial Spider and O-UNC-045, as operating a sustained adversary-in-the-middle campaign against financial services, legal, and other industries since April under extortion brands including Falcon, Helix, Pink, Redact, and BlackFile.

    Show sources