Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-09 ยท updated: 2026-08-09 ยท tags: [incident, vishing, unc6671, saas, mfa-bypass, aitm, financial-services, social-engineering] ยท confidence: high ยท affected_sectors: [financial-services, professional-services, technology] ยท au_impact: true

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

Google Threat Intelligence Group and Mandiant attributed a wave of vishing attacks to the data extortion group UNC6671, targeting financial services, private equity, and professional services. The attackers pose as IT help desk staff and call employees on their personal mobile devices, tricking them into spoofed login portals where AitM (Adversary-in-the-Middle) infrastructure intercepts credentials and MFA tokens. The group then uses automated scripts to exfiltrate data from Microsoft 365 and Okta environments.

Overview

Attribute Detail
Threat Actor UNC6671 (data extortion group)
Attributed by Google Threat Intelligence Group, Mandiant
Sector Financial services, private equity, professional services
Vector Vishing via personal mobile phones
Technique AitM (Adversary-in-the-Middle) phishing portals
Target Microsoft 365 and Okta credentials
Impact SaaS data exfiltration via automated scripts
Date 2026-08-07
Source The Hacker News

Key Tactics

  1. Attackers call employees on personal mobile devices (bypassing corporate phone security)
  2. Pretend to be IT help desk staff with a plausible pretext
  3. Direct victims to spoofed login portals with AitM infrastructure
  4. Intercept credentials and MFA tokens in real-time
  5. Use automated scripts to exfiltrate data from M365 and Okta

Significance

The use of personal mobile devices to bypass corporate security controls is a notable evolution in vishing operations. Traditional vishing targets corporate phones or VoIP; calling personal numbers allows attackers to reach employees outside of the organisations' security monitoring.

Mitigation

  1. Educate employees that IT help desk will never call and ask for credentials or MFA codes
  2. Implement number-verification or call-back procedures for any unsolicited IT support calls
  3. Deploy phishing-resistant MFA (FIDO2/WebAuthn) where possible
  4. Monitor for anomalous Okta and M365 access patterns

Related Pages

  • O Unc 066 โ€” Vishing threat actor using fake Microsoft Entra passkey enrollment (similar MFA bypass targeting M365)