SSO Compromise Now Fuels Bulk SharePoint Exfiltration
The real break is not the MFA bypass itself. Once UNC6671 gets into Okta or Microsoft 365, it uses that access as a launch point for scripted, high-volume cloud file collection that looks like legitimate post-login activity until the data is already gone.
Google Threat Intelligence Group says UNC6671, also tracked as BlackFile, has been running a vishing and AiTM campaign since early 2026 against dozens of organizations in North America, Australia, and the UK. The group targets Microsoft 365 and Okta, captures MFA, then uses Python and PowerShell to pull sensitive corporate data from cloud repositories such as SharePoint for later extortion.
That shifts the defender’s problem from account takeover to post-authentication abuse. A reset can stop the login, but it does not explain how much cloud data was already harvested, or whether the access pattern was a scripted burst that blended into normal SSO use.