Voice‑Phishing Extortion Campaign Targets Hedge Funds and Private‑Equity Firms – UNC6671/BlackFile Linked Group
What Happened — A wave of vishing (voice‑phishing) attacks has been linked to the UNC6671 extortion group, which operates under the BlackFile umbrella. The group has called employees at Point72, Millennium Management, Two Sigma, Citadel and several private‑equity firms, attempting to persuade them to grant remote‑access credentials. No public evidence of client‑data exfiltration has been disclosed, but the attacks illustrate a focused effort to breach high‑value financial institutions.
Why It Matters for Compliance & Audit Readiness
- SOC 2 Security – The scenario tests the effectiveness of access‑control policies, MFA enforcement, and privileged‑access monitoring that are core to the SOC 2 Security principle.
- Continuous‑Compliance – Documented evidence of phishing‑resistance training and incident‑response drills satisfies the “monitoring” and “risk mitigation” criteria auditors look for.
- Audit Trail – Capturing call‑record logs, credential‑request alerts, and remediation steps provides defensible proof of due diligence during a SOC 2 audit.
Who Is Affected
- Financial services (hedge funds, private‑equity, asset‑management)
- Legal and rating‑agency firms that serve the same client base
Recommended Actions
- Verify that all privileged‑access accounts require multi‑factor authentication and are protected by time‑bound, just‑in‑time (JIT) access controls.
- Conduct a targeted security‑awareness session on vishing techniques for any staff with remote‑access privileges; record attendance as audit evidence.
- Enable real‑time call‑recording and voice‑analysis alerts on corporate telephony systems to flag suspicious credential‑request calls.
Technical Notes – The campaign leverages social‑engineering (voice phishing) to harvest credentials for cloud and on‑premise environments. No CVE or software flaw is involved; the primary vector is human manipulation. Source: BleepingComputer