# UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: Google Threat Intelligence
- Author credit: Google Threat Intelligence Group; Mandiant
- Category: Cyber
- Original publication time: 2026-08-06T14:00:00Z
- First observed by NexusTechWire: 2026-10-01T20:28:45Z
- Original source: https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/
- NexusTechWire record: https://nexustechwire.com/news/news-7b5a120ec555064099c4

## The brief

Google Threat Intelligence and Mandiant say UNC6671 continued data-theft extortion after BlackFile's announced retirement, using several new brands while targeting financial and professional services. The report describes helpdesk impersonation and theft from enterprise cloud accounts, recommending phishing-resistant authentication and monitoring cloud activity. Shared infrastructure supports a connection between the brands, but the researchers acknowledge alternatives such as splinter groups or shared services.

AI-assisted NexusTechWire summary, checked against the linked source on 2026-10-01T23:11:41Z. Not independent reporting.

Read the full original: [Google Threat Intelligence](https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
