← Back to feed
PhishingEmerging1 sourceAug 17, 2026 · 20:41via CyberScoop

Details emerge on BlackFile’s recent attacks on financial companies

Brief

A cybercrime group responsible for a string of recent attacks against private equity firms, law firms and financial rating agencies remains active and continued to target new victims as of late last week, according to researchers.

BlackFile, which Google Threat Intelligence Group tracks as UNC6671 and associates more broadly with The Com , has been active since the start of the year, shifting its focus from one sector to the next.

“We have seen continued targeting against the financial sector with additional targeting of other organizations including in the med tech space,” Austin Larsen, principal threat analyst at GTIG, told CyberScoop.

The extortion group impersonates IT support in voice-phishing and social engineering attacks, and recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon.

Read more on CyberScoop