UNC6671 Vishing Campaigns Exploit Personal Phones to Compromise SaaS Data
UNC6671 employs vishing attacks targeting personal phones to intercept SaaS credentials via spoofed login portals and AitM infrastructure, enabling data exfiltration from cloud environments. The group leverages multiple extortion brands and social engineering to bypass MFA, shifting focus across sectors while demanding ransom payments.
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671.
"UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their
*** END OF TRANSMISSION ***