Support Channels Become the Access Point for Extortion

UNC3753 is getting inside by abusing the help desk, not by breaking software. Once a victim is talked into a screen-share or a legitimate remote management tool, the attacker can search for files, steer the victim into opening them, or steal data through the same trusted support channel. Google Mandiant and GTIG say the campaign hit dozens of U.S. professional, legal, and financial firms from January through May 2026. The stolen material included legal agreements, PII, and financial records, and some intrusions escalated to fake technicians showing up in person and copying data to USB media. That mix changes the defense problem. Patching and anti-phishing filters do not stop a caller who convinces staff to hand over the session themselves, and the legal and financial target set raises the pressure to pay quietly when the stolen files carry reputational or regulatory weight.

Part of the PlainSec briefing for 2026-06-08

Sources