Skip to content

UNC6671: Vishing Attacks on Personal Phones Target SaaS Data

Bottom line: UNC6671 contacts employees via personal mobile numbers posing as an IT helpdesk in order to extort access to the SaaS environments of financial services and consulting firms.

The extortion group UNC6671 is currently attacking companies in the financial services, private equity and professional services sectors with voice phishing campaigns. Notably, the attackers deliberately contact employees via their personal phone numbers in order to circumvent corporate policies and call-verification training.

According to current reports, UNC6671 actors pose as IT helpdesk staff on the phone, claiming that a mandatory, urgent security migration is pending. The group is attributed to a financially motivated data extortion campaign and has specifically targeted companies in the financial services, private equity and professional services sectors.

The key tactical difference from previous vishing waves lies in the contact method: instead of operating via the company phone number or official business communication channels, UNC6671 contacts targets on their personal mobile phones. This allows the attackers to bypass security measures based on monitoring, filtering, or logging calls made over corporate infrastructure, and to reach employees in a context where they are less prepared for social engineering attempts.

For CISOs, this means that purely technical controls at the corporate level — such as call authentication via corporate PBX systems or callback verification via business numbers — are ineffective against this type of attack. Since the goal of the campaign is access to SaaS environments, priority should be given to identity and access controls for SaaS applications, in particular multi-factor authentication that is resistant to social engineering (e.g., FIDO2/hardware tokens instead of phone-based confirmation), as well as strict processes for helpdesk identity verification.

In practice, it is advisable to explicitly extend awareness training to cover scenarios in which purported IT support calls arrive on personal devices, and to communicate clear, verifiable escalation paths through which employees can report suspicious calls regardless of the phone number used. In addition, monitoring processes for unusual login activity and permission changes in SaaS platforms should be tightened, as this is typically the next step following a successful vishing attack.


Source: thehackernews.com · Published August 7, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: