Threats · 52 days ago
A rebrand does not break this operation. GTIG says the real risk is the same vishing-and-extortion crew keeping its playbook, infrastructure, and victims as it cycles through BlackFile, Redact, Pink, Helix, and Falcon names. Brand loss changes the label, not the access path: a fake help-desk call still gets the attacker into a live cloud session.
Google ties the brands together through matching phishing templates, shared infrastructure conduits, and overlapping victimology. The group targets employees on personal devices, pushes them to spoofed login pages, captures credentials and MFA in the middle, then keeps the session open to work inside Microsoft 365 or Okta accounts and pull data.
That means takedowns and attribution by brand alone will miss the operating core. The public extortion name can change fast, but the same operators can keep stealing cloud sessions and extorting victims under a new front.
3 sources covering this story
Vishing Extortion Group UNC6671 Rebrands After Making Millions
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.
Google Links Redact Extortion Group to BlackFile Rebrand
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns
UNC6671 has rebranded from BlackFile to REDACT while diversifying its extortion operations across multiple brands, including FALCON, HELIX, and PINK.
Part of the PlainSec briefing for 2026-08-08