UNC6671 is calling employees at financial firms and posing as IT.
Mandiant says the callers reach personal phones, spoof helpdesk numbers, and use urgent passkey or MFA changes to move employees into attacker-controlled flows.
The sign-in control may be strong. The person telling the employee what to do has not been verified.
The call sounds like a security fix
The attack begins with a phone call, not a sign-in page.
An employee receives a call on a personal phone from someone claiming to be a coworker or internal IT. The displayed number may be the organization's legitimate helpdesk. The request sounds protective and urgent: enroll a passkey or update MFA now.
The caller then directs the employee to an attacker-controlled enrollment site designed to capture credentials and MFA tokens. Google Threat Intelligence Group and Mandiant say they observed UNC6671 infrastructure aimed at financial services, private equity, law firms, and financial-rating agencies.
Google did not name victims, and targeting does not establish a successful compromise.
Passkeys are not the problem
This campaign does not make passkeys unsafe. Google recommends phishing-resistant authentication, including passkeys and FIDO2 security keys, because WebAuthn binds authentication to the legitimate relying-party domain. That makes lookalike domains and adversary-in-the-middle proxies far less useful.
Google's recommendations also include managed devices, consistent SSO controls, shorter sessions, trusted network restrictions, credential protection, and monitoring for suspicious enrollment or challenge patterns.
Those controls protect authentication. They do not establish that the person giving the instruction is really from IT. UNC6671 is exploiting the support conversation that comes first.
September update: fake IT calls target executives
Arctic Wolf's September 3 research, covered by Help Net Security on September 8, identifies directors, vice presidents and other executive staff as the most frequent targets of these fake IT calls. Attackers intercepted credentials and MFA approvals through fake Microsoft 365 sign-in flows, then used stolen sessions to collect data from SharePoint, OneDrive, Exchange and Box. Arctic Wolf observed no endpoint malware deployment or network-based lateral movement in this cluster.
The researchers track it as PREY-0058 and describe substantial behavioral overlap with UNC6671. That does not establish that every associated extortion brand is the same actor.
The practical takeaway: executive support should not be an exception to caller verification. An executive receiving an unexpected IT call needs a trusted way to verify the person before following security-change instructions. Keep phishing-resistant authentication, access restrictions and session monitoring in place too; caller verification is an additional control, not their replacement.
Employees need a way to verify IT
Caller ID displays a number. It does not prove who is speaking. Neither does knowledge of internal terminology or an urgent request.
When someone calls as IT, the employee should start from a known company-controlled destination—not a URL or number supplied during the call. There, the employee can check a short-lived request identifying the support representative and the action being discussed. If no verified request exists, the employee stops and contacts support through an established channel.
This is the workflow we are building Fctr to support. Helpdesks verify employees before recovery or account changes. Employees verify people claiming to be IT before following sensitive instructions.
Fctr does not create the target application's sign-in session or authorize the underlying account change. It establishes who is participating before the support workflow continues.
Sources
- Google Threat Intelligence Group and Mandiant — UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
- Arctic Wolf Labs — Cloud Data Theft and Extortion via IT Help Desk Vishing and Residential Proxies
- Help Net Security — IT help-desk vishing tricks executives into handing over Microsoft 365 access
- TechCrunch — Google says hackers are calling financial firm employees to hack and extort victims