Home/Threat Intelligence/CBN-2026-031
HighAdvisoryTLP: CLEARCBN-2026-031 · 07 Aug 2026
UNC6671 phones staff on their personal mobiles and talks them into a fake passkey enrolment
Operators spoof your help-desk number, call employees on personal phones, and tell them to enrol a passkey immediately. The page is a reverse proxy. Once inside they register their own MFA, delete yours, and delete the alert emails.
At a glance
Affected
Microsoft 365, Entra ID and Okta tenants. Targeting moved upmarket through July — financial services, private equity and law firms.
Impact
Full account takeover with attacker-controlled MFA, bulk exfiltration of mail, SharePoint documents and Teams data, then extortion under a rotating set of brand names.
Action
Enforce phishing-resistant MFA through Conditional Access Authentication Strengths, require compliant devices, and hard-gate every help-desk MFA reset behind out-of-band verification.
Client status
Managed tenants run Authentication Strengths with FIDO2 or Entra passkeys and device compliance conditions, which breaks the proxy outright. Help-desk verification procedure is the piece clients must own.
Detail
The pretext is well chosen. Somebody calls an employee, the caller ID shows the company help desk, and the message is that a mandatory security migration requires them to enrol a FIDO2 passkey now. The employee is being asked to improve their security, urgently, by a number they recognise. Almost nothing in standard awareness training covers this shape of attack.
The calls go to personal mobiles deliberately — outside corporate telephony, outside any call recording, outside anything the security team can see. The victim is sent to a company-specific subdomain of a passkey-themed root domain, hosted on commercial VPN infrastructure, running a reverse proxy that intercepts the credentials and the live MFA response and captures the session.
The clean-up step is what makes it stick
Once inside Microsoft 365, Entra ID or Okta, the operators register their own MFA device, strip the legitimate methods, and then delete the password-reset confirmations and MFA-change notification emails from the victim's mailbox. The user gets no warning that anything changed. That last step is the difference between an incident detected in an hour and one detected in a fortnight.
An industrial operation
Google Threat Intelligence Group and Mandiant track this as UNC6671, running rotating extortion brands — BlackFile, retired in May; REDACT from late June; PINK, HELIX and FALCON. Unit 42 tracks related clusters separately; CrowdStrike calls the umbrella Cordial Spider.
Eighteen BlackFile-linked Bitcoin wallets received 141.65 BTC — around USD 10.69 million — between January and May. Initial demands ran USD 1 to 3 million, negotiated down 50 to 75%, with 53% of cases settling near USD 750,000. Domain registration tempo went from one every 2.2 days in April and May to one every 1.6 days in June and July, including seven in a 72-hour spike in late July.
Two controls that actually stop this
First, phishing-resistant MFA enforced through Conditional Access Authentication Strengths. WebAuthn binds the credential to the origin, so the reverse proxy has nothing to relay. The irony that the lure is a passkey enrolment is not lost on us — real passkeys are the countermeasure.
Second, the help desk. No MFA reset without out-of-band verification: a callback to a number on record, a video identity check, or in person. And a stated policy that inbound calls to personal mobiles claiming to be internal IT are to be hung up on and reported. That policy costs nothing and closes the front door.
One detection worth adding today: in the Microsoft 365 Unified Audit Log, treat FileAccessed with the same severity as FileDownloaded. These operators read at scale rather than downloading, and most alerting rules only watch the second one.
If you find evidence of this activity, do not begin remediation before preserving evidence — console and appliance audit logs are frequently short-retention and will roll off. Acronis MDR provides around-the-clock detection and response for covered estates; otherwise reach us through the contact page and we will advise on preservation before containment.
Sources
Cybernalyst's analysis and recommendations are our own. The underlying research is credited below — please read the original reporting.
- UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud EnvironmentsTyler McLellan and Austin Larsen·Google Threat Intelligence Group / Mandiant·6 August 2026
- UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS DataRavie Lakshmanan·The Hacker News·7 August 2026