The threat actor group UNC6671 has been conducting vishing attacks targeting personal mobile phones of enterprise employees to steal SaaS credentials and exfiltrate data from cloud environments like Microsoft 365 and Okta. Using social engineering, spoofed help desk calls, and adversary-in-the-middle phishing portals, they intercept login credentials and multi-factor authentication tokens to gain persistent access and lateral movement across SaaS ecosystems. The group operates multiple extortion brands, demands ransoms often negotiated down to hundreds of thousands of dollars, and highlights the necessity of phishing-resistant MFA and vigilant identity provider monitoring to mitigate such risks.
https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html

