Voice Phishing Extortion Gang Rebrands Multiple Times After Making Millions
Security researchers have identified a cybercriminal group, tracked under the name UNC6671, that uses voice phishing—commonly known as vishing—to extort money from victims. The group initially operated under the name BlackFile before reportedly making significant profits from its scams and subsequently rebranding under several new identities: Redact, Pink, Helix, and Falcon.
Vishing attacks typically involve criminals impersonating trusted contacts, such as IT support staff, bank representatives, or company executives, over the phone to trick victims into handing over sensitive information, granting system access, or making payments. The rebranding pattern seen with this group suggests an effort to evade detection, distance new campaigns from past exposure, and continue operating profitably under a fresh identity.
For Australian small businesses, this serves as a reminder that vishing remains a persistent and evolving threat. Attackers frequently target employees directly, relying on social engineering rather than technical exploits, which means staff awareness is often the strongest line of defence. As groups like this rebrand and refine their tactics, businesses should treat unsolicited or urgent phone requests for sensitive information or payments with caution, regardless of how convincing the caller may seem.