Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

UNC6671, operating as ‘BlackFile,’ is running an active extortion campaign that combines targeted phone calls with real-time credential interception to bypass multi-factor authentication across Microsoft 365, Okta, and related SaaS platforms. The group has compromised organizations across North America, Australia, and the UK since early 2026, with reported file exfiltration and ransom demands in the millions of dollars according to Google Threat Intelligence. A suspected logging gap in Microsoft 365 means mass file theft via API may be misclassified as routine access, potentially making this campaign difficult to detect with standard SOC tooling.

Author

Tech Jacks Solutions