Vishing Crew Turns Helpdesks Into Credential Farms
BlackFile turns the helpdesk into the weak point. Its operators call employees from spoofed numbers, pose as IT support, and use the stolen credentials to get into corporate accounts and extort the victim. The standard response of tightening email security misses the real problem: voice-based social engineering can bypass the controls that protect the inbox.
Unit 42 links the group, also tracked as CL-CRI-1116, UNC6671, and Cordial Spider, to a wave of attacks on retail and hospitality firms since February 2026. RH-ISAC says the crew uses fake login pages, stolen one-time passcodes, and device registration to get around multifactor authentication. Unit 42 also gave the group moderate-confidence ties to The Com, a criminal network known for recruitment, extortion, violence, and CSAM-related activity.
The threat is broader than ransom demands. If that link holds, BlackFile may be part of a criminal ecosystem that mixes credential theft with coercion and abuse, which raises the stakes for any organization that treats this as a simple extortion campaign.
BlackFile actively extorting data-theft victims in retail and hospitality sector
Some attackers, which researchers link to The Com, have swatted company executives to increase leverage and pressure victims to pay their ransom demands.
New BlackFile extortion group linked to surge of vishing attacks
A new financially motivated hacking group tracked as BlackFile has been linked to a wave of data theft and extortion attacks against retail and hospitality organizations since February 2026.