By Interestana AI Editorial — AI-drafted, human-overseen. How we report
UNC6671 Vishing Attacks Target Personal Phones for SaaS Data

A sophisticated data extortion group identified as UNC6671 has initiated a new campaign of cyber attacks, primarily targeting employees within the financial services, private equity, and professional services sectors. This group is notably employing voice phishing, commonly known as vishing, as its primary vector for infiltration. UNC6671 operatives are impersonating IT help desk personnel, contacting enterprise employees with urgent requests related to mandatory security migrations. The attackers leverage social engineering tactics to persuade individuals to grant access to their personal mobile devices, which are often used for work-related activities and may contain credentials for Software-as-a-Service (SaaS) applications.
During these vishing calls, UNC6671 actors instruct victims to download specific applications or visit malicious websites, ostensibly to complete the security migration process. Once the employee complies, the threat actor gains the ability to remotely access the device. This access allows UNC6671 to steal sensitive information, including authentication tokens and credentials, which are then used to access corporate SaaS accounts. The group's objective is to exfiltrate data and subsequently engage in extortion, demanding payment to prevent the public release of the stolen information. The attacks are characterized by their focus on personal devices, highlighting a growing trend where the lines between personal and professional technology blur, creating new attack surfaces for cybercriminals.
Mandiant, a Google Cloud company, has been tracking UNC6671's activities and noted that the group's operational security is relatively robust, making attribution challenging. However, the consistent use of vishing and the specific targeting of SaaS data provide key indicators of their modus operandi. The group's persistence and adaptability in refining their tactics underscore the evolving nature of cyber threats. By exploiting the trust employees place in their IT departments and the increasing reliance on mobile devices for business operations, UNC6671 is effectively bypassing traditional network security perimeters. The success of these attacks emphasizes the critical need for enhanced employee training on cybersecurity best practices, particularly concerning unsolicited communications and the security of personal devices used for work purposes.
The implications of UNC6671's tactics extend beyond individual data breaches. For organizations in the targeted sectors, the compromise of SaaS accounts can lead to significant financial losses, reputational damage, and disruption of business operations. The group's focus on extortion means that victims face the difficult decision of whether to pay a ransom, which is often discouraged by cybersecurity experts due to the lack of guarantee that data will not be leaked or that the group will cease future attacks. The ongoing nature of these attacks suggests that UNC6671 is actively seeking to monetize stolen data and may continue to evolve its methods to circumvent security measures. The reliance on personal devices as the initial point of compromise also points to a need for organizations to implement stricter policies regarding device usage and to provide more comprehensive security solutions that extend to employee-owned hardware.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.