BlackFile Cybercrime Group Continues Targeting Financial Sector with New Extortion Demands

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

A cybercrime group known as BlackFile continues to target the financial sector, with reports indicating that it remains active and has been shifting its focus to new victims. This group, tracked by the Google Threat Intelligence Group as UNC6671, has been implicated in a series of attacks against private equity firms, law firms, and financial rating agencies since the beginning of the year.

According to Austin Larsen, a principal threat analyst at GTIG, BlackFile has been particularly aggressive in its targeting of the financial sector, while also expanding its operations to include organizations in the medical technology space. The group employs voice-phishing and social engineering tactics, often impersonating IT support to gain access to their targets.

Recently, BlackFile has divided its extortion efforts among four brands—Redact, Pink, Helix, and Falcon—utilizing shared infrastructure. Reports indicate that several organizations received new extortion demands from Redact in the past week. The group’s demands typically start around $3 million, although payments have been negotiated down to less than $1 million in recent cases.

BlackFile’s activities have affected a wide range of industries, including healthcare, technology, transportation, logistics, and retail. Larsen noted that the group primarily targets large organizations, stating, “This is big-game hunting.” The group is estimated to target an average of 1.5 new victims daily, highlighting the persistent threat it poses.

Some victims have reported receiving threatening messages and experiencing escalated tactics, including swatting incidents. The attackers often recruit lower-level individuals to make voice phishing calls, which are used to gain initial access to their targets. Mandiant incident responders have encountered BlackFile frequently, having assisted over two dozen organizations that were compromised by the group since January.

While voice-based phishing attacks are not new, BlackFile’s consistent effectiveness across various sectors underscores the importance of addressing human vulnerabilities in cybersecurity. For more details, refer to the full report by CyberScoop.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Air Force retires EC-130H Compass Call, replacing it with EA-37B

WASHINGTON — The Air Force has formally retired the EC-130H Compass Call, concluding over 40 years of operations for this electronic attack aircraft. The...

AI-Driven Research Uncovers HEIF Heist Vulnerability in Popular Software Decoders

Researchers have identified a significant vulnerability, dubbed the "HEIF Heist," in popular software decoding tools that could expose major internet platforms and enterprise services...

North Korean Threat Actor Jade Sleet Compromises Indian IT Provider Using FLATROOF and ROOFDECK Backdoors

The North Korean threat actor known as Jade Sleet has been linked to the compromise of a smaller Indian IT services organization, underscoring the...

Seclore Enhances Data-Centric Security Solutions Across Middle East, Turkey, and Africa

Seclore Expands Data-Centric Security Solutions Across META Seclore has unveiled significant advancements in its data-centric security solutions during GISEC Global 2026, focusing on the Middle...