Threats & Adversaries · Credential Theft
Redact Rebrand Hides the Same Extortion Playbook A rebrand does not break this operation. GTIG says the real risk is the same vishing-and-extortion crew keeping its playbook, infrastructure, and victims as it cycles through BlackFile, Redact, Pink, Helix, and Falcon names. Brand loss changes the label, not the access path: a fake help-desk call still gets the attacker into a live cloud session.
Google ties the brands together through matching phishing templates, shared infrastructure conduits, and overlapping victimology. The group targets employees on personal devices, pushes them to spoofed login pages, captures credentials and MFA in the middle, then keeps the session open to work inside Microsoft 365 or Okta accounts and pull data.
That means takedowns and attribution by brand alone will miss the operating core. The public extortion name can change fast, but the same operators can keep stealing cloud sessions and extorting victims under a new front.
3 sources · Aug 7
Timeline Sources Aug 7 SecurityWeek
Vishing Extortion Group UNC6671 Rebrands After Making Millions
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.
original Aug 7 Infosecurity Magazine
Google Links Redact Extortion Group to BlackFile Rebrand
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns
original Aug 6 Mandiant
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments | Google Cloud Blog
UNC6671 has rebranded from BlackFile to REDACT while diversifying its extortion operations across multiple brands, including FALCON, HELIX, and PINK.
original Part of the PlainSec briefing for 2026-08-08
Every edition of this story: Redact Rebrand Hides the Same Extortion Playbook
More from today
Threats & Adversaries · Credential Theft
Redact Rebrand Hides the Same Extortion Playbook A rebrand does not break this operation. GTIG says the real risk is the same vishing-and-extortion crew keeping its playbook, infrastructure, and victims as it cycles through BlackFile, Redact, Pink, Helix, and Falcon names. Brand loss changes the label, not the access path: a fake help-desk call still gets the attacker into a live cloud session.
Google ties the brands together through matching phishing templates, shared infrastructure conduits, and overlapping victimology. The group targets employees on personal devices, pushes them to spoofed login pages, captures credentials and MFA in the middle, then keeps the session open to work inside Microsoft 365 or Okta accounts and pull data.
That means takedowns and attribution by brand alone will miss the operating core. The public extortion name can change fast, but the same operators can keep stealing cloud sessions and extorting victims under a new front.
3 sources · Aug 7
Timeline Sources Aug 7 SecurityWeek
Vishing Extortion Group UNC6671 Rebrands After Making Millions
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.
original Aug 7 Infosecurity Magazine
Google Links Redact Extortion Group to BlackFile Rebrand
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns
original Aug 6 Mandiant
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments | Google Cloud Blog
UNC6671 has rebranded from BlackFile to REDACT while diversifying its extortion operations across multiple brands, including FALCON, HELIX, and PINK.
original Part of the PlainSec briefing for 2026-08-08
Every edition of this story: Redact Rebrand Hides the Same Extortion Playbook
More from today