UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
Google Threat Intelligence Group and Mandiant attributed a wave of vishing attacks to the data extortion group UNC6671, targeting financial services, private equity, and professional services. The attackers pose as IT help desk staff and call employees on their personal mobile devices, tricking them into spoofed login portals where AitM (Adversary-in-the-Middle) infrastructure intercepts credentials and MFA tokens. The group then uses automated scripts to exfiltrate data from Microsoft 365 and Okta environments.
Overview
| Attribute | Detail |
|---|---|
| Threat Actor | UNC6671 (data extortion group) |
| Attributed by | Google Threat Intelligence Group, Mandiant |
| Sector | Financial services, private equity, professional services |
| Vector | Vishing via personal mobile phones |
| Technique | AitM (Adversary-in-the-Middle) phishing portals |
| Target | Microsoft 365 and Okta credentials |
| Impact | SaaS data exfiltration via automated scripts |
| Date | 2026-08-07 |
| Source | The Hacker News |
Key Tactics
- Attackers call employees on personal mobile devices (bypassing corporate phone security)
- Pretend to be IT help desk staff with a plausible pretext
- Direct victims to spoofed login portals with AitM infrastructure
- Intercept credentials and MFA tokens in real-time
- Use automated scripts to exfiltrate data from M365 and Okta
Significance
The use of personal mobile devices to bypass corporate security controls is a notable evolution in vishing operations. Traditional vishing targets corporate phones or VoIP; calling personal numbers allows attackers to reach employees outside of the organisations' security monitoring.
Mitigation
- Educate employees that IT help desk will never call and ask for credentials or MFA codes
- Implement number-verification or call-back procedures for any unsolicited IT support calls
- Deploy phishing-resistant MFA (FIDO2/WebAuthn) where possible
- Monitor for anomalous Okta and M365 access patterns
Related Pages
- O Unc 066 โ Vishing threat actor using fake Microsoft Entra passkey enrollment (similar MFA bypass targeting M365)