Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

Helpdesk Calls Become the Front Door in Attacks on Wall Street Firms

Helpdesk Calls Become the Front Door in Attacks on Wall Street Firms
Photo by Ann H on Pexels

The UNC6671 extortion group has been linked to voice-phishing attacks against hedge funds, private-equity firms and other financial organizations. Attackers impersonate corporate helpdesks, capture cloud credentials and session cookies, and use compromised single sign-on accounts to extract data from connected services.

News Date: 2026-08-06

A campaign targeting some of the financial sector's most valuable organizations shows that a convincing telephone call can still defeat an expensive security stack. The activity, tracked by Google Threat Intelligence Group as UNC6671, has reportedly targeted hedge funds, private-equity firms, law firms and financial-rating agencies using voice phishing and cloud-focused extortion.

From Helpdesk Impersonation to Cloud Access

The attackers call employees on personal mobile phones while posing as members of the corporate helpdesk. They typically claim that the employee must update multifactor authentication settings or enroll a passkey. The victim is then directed to a counterfeit corporate website equipped with an adversary-in-the-middle phishing system.

This approach can capture credentials and active session cookies in real time. Once an attacker controls a Microsoft 365 or Okta single sign-on account, the initial compromise may provide access to numerous connected cloud applications. Automated tools can then collect data at scale, while the attackers may delete password-reset messages and security notifications to delay discovery.

Google reportedly connects the intrusion team to the operation previously branded as BlackFile. The group is believed to use several public extortion identities, although one of the named brands has disputed parts of that assessment. Mandiant is assisting several dozen affected organizations, indicating that the campaign extends beyond a handful of attempted intrusions.

Why Financial Firms Are Attractive

Investment businesses hold market-sensitive documents, investor information, legal records and communications involving major transactions. Even without encrypting systems, criminals can threaten considerable reputational and regulatory damage by stealing this material.

Defensive Priorities

  • Require independent verification for unsolicited helpdesk calls.
  • Restrict authentication changes to managed workflows and approved devices.
  • Monitor new session creation, mailbox rule changes and unusual cloud downloads.
  • Use phishing-resistant authentication while recognizing that session theft remains possible.
  • Provide employees with a rapid channel for reporting suspicious calls.

In my view, the central lesson is that identity security cannot stop at MFA enrollment. Organizations must monitor what happens after authentication and treat helpdesk procedures as privileged security controls. A trusted voice on the telephone should never be enough to authorize a change that can unlock an entire cloud environment.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path