CuraSec

Act active

UNC6671/BlackFile extortion group actively targets financial firms

2026-08-07 00:21 UTC · BleepingComputer · read the source ↗ #threat-actors#extortion#financial-sector
  • Engineer — Skip
  • SOC/IR — Learn: Actor profile useful for financial-sector defenders: UNC6671 is tied to BlackFile and is running an active extortion campaign against hedge funds and PE firms, but no IOCs, TTPs, or detection-ready technical details are available in this item yet.
  • Leader — Act: If your organization is in financial services, brief leadership now on the active UNC6671 extortion campaign targeting hedge funds and private-equity firms; verify whether your firm has received any suspicious outreach and confirm IR retainer readiness.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.