UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
Summary
A data extortion group named UNC6671 is conducting cyber attacks against financial services, private equity, and professional services firms. These attacks primarily utilize voice phishing (vishing) where the attackers impersonate IT help desk staff to trick employees into revealing sensitive information.
IFF Assessment
The article describes a threat actor group employing vishing tactics to steal data, which poses a direct risk to organizations and their data.
Defender Context
This attack highlights the continued effectiveness of social engineering tactics like vishing, even against sophisticated organizations. Defenders should reinforce employee training on identifying and reporting suspicious communications, especially those claiming to be from IT support and demanding urgent action. Multi-factor authentication and robust incident response plans are also crucial to mitigate the impact of compromised credentials.