highPhishing

UNC6671 Vishing Campaign Targeting SaaS Data

First seen Aug 8, 2026 · Updated Aug 8, 2026

vishingsocial-engineeringsaasdata-extortioncredential-thefthelp-desk-impersonationagent-relevant

UNC6671 is a data extortion group conducting voice phishing attacks against financial services, private equity, and professional services firms. The group impersonates IT help desk staff and contacts employees via personal phones to coerce urgent 'security migration' actions that grant attackers access to SaaS environments and enterprise data.

Technical Analysis

UNC6671 uses vishing (voice phishing) as its primary initial access vector, calling employees directly on personal devices while posing as internal IT support conducting mandatory security migrations. This social engineering approach bypasses many corporate email/phishing controls since it targets personal communication channels and voice interaction rather than malicious links or attachments, often manipulating victims into installing remote access tools, approving MFA prompts, or disclosing SaaS credentials/OAuth tokens. The stolen access is then leveraged for data extortion, likely involving bulk exfiltration from SaaS platforms such as Salesforce, Microsoft 365, or similar cloud services used by financial and professional services firms. Organizations that integrate AI agents or LLM-based tools with these same SaaS platforms (e.g., agents with delegated access to CRM, email, or document stores via API keys or OAuth tokens) face elevated risk, since credentials harvested through vishing could be reused to access agent-connected data sources or hijack agent tool permissions, enabling broader unauthorized data exposure or manipulation.

Affected Systems

Enterprise SaaS platforms (e.g., CRM, email, cloud storage), employee personal mobile devices used for work communication, IT help desk verification processes, MFA/SSO systems tied to SaaS accounts

Indicators of Compromise

  • No specific hashes, IPs, or domains disclosed in source reporting; IOCs primarily behavioral (vishing calls to personal phone numbers impersonating IT help desk staff)

Remediation Steps

  1. 1

    Strengthen Help Desk Verification

    Implement strict multi-factor identity verification protocols for any IT support requests, especially those involving credential resets or security migrations, and never rely solely on caller-provided information.

  2. 2

    Employee Awareness Training

    Train staff to recognize vishing tactics, including calls to personal phones claiming to be IT support, and establish clear internal channels to verify legitimacy before taking action.

  3. 3

    Restrict Personal Device Use for Corporate Access

    Limit or monitor use of personal phones for receiving corporate security-related communications; route sensitive requests through verified corporate channels only.

  4. 4

    Enforce Phishing-Resistant MFA

    Deploy FIDO2/hardware-based MFA to reduce the risk of social-engineered MFA approval or OTP relay attacks.

  5. 5

    Audit SaaS and API Access

    Review and rotate API keys, OAuth tokens, and service account credentials tied to SaaS platforms and any AI agent integrations to prevent reuse of compromised credentials.

  6. 6

    Monitor for Anomalous SaaS Activity

    Implement UEBA/SIEM detection for unusual login patterns, data exports, or permission changes in SaaS environments consistent with extortion-driven data theft.

Industries Most Exposed

financial servicesprivate equityprofessional services

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.