you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 17 min ago 255 onions tracked
home / news / market watch
26 August 2026 market watch 5 min read

BlackFile and the four faces of one extortion crew: inside The Com's vishing franchise

Since January 2026, a wave of brazen attacks against some of the most security-conscious companies in the world has followed a single blueprint: a phone call to an IT help desk, a hijacked identity, and then a multi-million-dollar extortion demand backed by threats of data publication and physical violence. Google Cloud Threat Intelligence now tracks the group behind it as UNC6671, better known by its brand name BlackFile, and describes it as one of the most aggressive new entrants in the financial-sector threat landscape (Google Cloud).

One operator, four brands

The defining feature of the campaign is franchising. Rather than operating under a single name, BlackFile has run its extortion through at least four victim-facing brands: Redact, Pink, Helix and Falcon. Analysts assessed the brands share infrastructure, tooling and personnel, meaning victims who researched one leak site often had no idea they were dealing with the same small group behind all four. This mirrors a broader pattern in which established crews rebrand their shaming sites after unwanted publicity while keeping operations intact. The group is affiliated with The Com, the loose English-speaking criminal ecosystem also known as the Com or Scattered Spider extended universe, whose members have specialized for years in social engineering rather than malware. That lineage shows in the tradecraft: intrusions begin with voice phishing calls aimed at help desks and employees, convincing targets to hand over credentials or approve multi-factor prompts, after which the actors move into cloud environments and harvest whatever can be used as leverage.

Wall Street in the crosshairs

The target list reads like an index of American finance. Reporting identified attacks and attempted approaches against private equity giants Blackstone and Bain Capital, ratings agency Moody's, derivatives marketplace CME Group and Apollo Global Management (CyberScoop). Apollo subsequently confirmed a data breach stemming from a social engineering attack, becoming the first of the named firms to publicly disclose that the crew succeeded against it. Financial firms are attractive targets precisely because of what sits on their servers: investor correspondence, portfolio company records and deal documents whose exposure carries reputational and regulatory consequences far beyond ordinary customer data.

Demands calibrated downward from $3 million

The economics of the scheme follow the industry-standard opening-gambit pattern. Initial demands have started at roughly $3 million, with negotiations typically settling below $1 million before payment. Investigators stress that the published figure is theater; the real number is whatever the victim's negotiators can be talked into. The gap between ask and settlement is itself useful intelligence for defenders, because it signals a group optimizing for volume over maximum payout per victim. Mandiant, Google Cloud's incident response arm, has been engaged by more than 25 victims of the activity cluster since January 2026, a caseload that makes BlackFile one of the fastest-growing extortion operations currently tracked. The scale is striking given how few people actually run it: fewer than a dozen core operators direct the campaign, while hundreds of recruited callers execute the voice phishing. It is effectively a call-center business model applied to cybercrime, with the founders supplying infrastructure, targets and negotiation playbooks while a rotating workforce of mostly young English speakers makes the calls.

Swatting as a second lever

What separates BlackFile from conventional ransomware crews is its willingness to escalate beyond the keyboard. Victims who resist have reportedly faced swatting incidents, in which fraudulent emergency calls dispatch armed police to executives' homes. This physical-intimidation layer converts a data breach into a personal safety crisis and is designed to panic leadership teams into paying before legal and incident response processes can catch up. Extortion built on impersonation and fear of authorities is not new, as we covered in our earlier piece on impersonation and extortion scams, but applying it against Fortune 500 executives marks an escalation in both audacity and payoff.

The pattern behind the phones

For defenders, the uncomfortable lesson is that none of the documented intrusions required zero-days or exotic malware. They required a phone and a confident caller. Organizations in finance should treat these habits as table stakes:
  • Harden help desk identity verification with callbacks to registered numbers, never numbers supplied during the incident call.
  • Treat MFA prompt bombing as an attack signal and enforce number-matching plus hardware-backed factors for privileged accounts.
  • Pre-brief executives on swatting risk so an emergency at home does not translate into ransom pressure at work.
The broader takeaway matches what security teams learned from previous Com-affiliated campaigns: technology controls fail quietly when the human verification layer is weak. BlackFile's four-brand structure may fragment under law enforcement pressure eventually, but with hundreds of recruiters still dialing and Mandiant responding to new cases weekly, the operation shows no sign of slowing as the third quarter closes. The full technical breakdown of the group's cloud-focused tooling is available in Google's original report (Google Cloud Threat Intelligence), and CyberScoop's continuing coverage tracks each newly disclosed victim (CyberScoop).

more notes

all news ›