A recent series of cyber incidents has drawn attention to the data‑extortion group UNC6671, whose latest tactics involve vishing—voice phishing—directed at employees’ personal phones.
UNC6671 has long targeted financial services, private equity, and professional services firms, but the current wave is distinguished by its use of legitimate phone lines to reach staff in a conversational manner.
The attackers typically pose as IT help‑desk personnel, claiming to facilitate an urgent, mandatory migration to a new SaaS platform. They urge recipients to provide credentials and, in some cases, to download a remote‑admin tool that grants them access to the target system.
Because the calls come from personal devices, many employees are less likely to suspect malicious intent, especially when the voice script mimics standard corporate support procedures.
Once inside, the threat actors harvest SaaS login data and other internal information. The stolen data can be leveraged for further attacks or sold on underground markets.
The implications for affected firms are significant. A breach of SaaS credentials can lead to regulatory fines, loss of client trust, and exposure of sensitive financial data.
In response, security teams are urged to enforce multi‑factor authentication on all corporate applications, regardless of device type.
Additionally, organizations should adopt zero‑trust policies that treat any remote access request with scrutiny, and limit the use of personal devices for business operations.
Employee awareness training is also critical; staff should be instructed to verify the identity of callers through a secondary channel before sharing credentials or installing software.
Firms are advised to conduct regular audits of phone usage, enforce device management policies, and monitor for anomalous traffic that could indicate a vishing attempt.