UNC6671 Vishing Attacks Target Employees’ Personal Phones for SaaS Data

Data extortion group UNC6671 is using vishing attacks to impersonate IT help desk staff and steal SaaS credentials from employees' personal phones in financial and professional services sectors.

Why it matters

This vishing campaign leverages social engineering to circumvent enterprise security controls by targeting employees’ personal devices, increasing the risk of unauthorized access to critical SaaS data.

SOC impact

Monitor for unusual or suspicious calls impersonating IT personnel to employees’ personal phones. Investigate any reported credential disclosures or account anomalies related to SaaS applications. Validate whether employee personal devices have been targeted and assess potential exposure of SaaS credentials.

Recommended actions

  1. Identify employees who have reported suspicious vishing calls or credential requests
  2. Review authentication logs of SaaS applications for unusual access patterns
  3. Monitor help desk interaction records for anomalies matching impersonation tactics
  4. Assess personal device security awareness and potential impact
  5. Investigate any reported data extortion attempts linked to this campaign

Executive Summary

The data extortion group UNC6671 is conducting targeted vishing attacks focused on employees’ personal phones within financial and professional services organizations. By impersonating IT help desk staff, the threat actors aim to acquire SaaS credentials through social engineering, bypassing traditional enterprise defenses.

This approach exploits trust in personal communications, thereby increasing operational risk from compromised accounts and potential data exposure. Security teams should augment monitoring of SaaS authentication data and validate any reported incidents involving personal devices. Understanding this tactic is crucial for detecting suspicious activity and mitigating credential theft risks associated with external vishing campaigns.

SOC Impact

Monitor for unusual or suspicious calls impersonating IT personnel to employees’ personal phones. Investigate any reported credential disclosures or account anomalies related to SaaS applications. Validate whether employee personal devices have been targeted and assess potential exposure of SaaS credentials.

Authentication and Personal Device Validation

  • Identify employees who have reported suspicious vishing calls or credential requests
  • Review authentication logs of SaaS applications for unusual access patterns
  • Monitor help desk interaction records for anomalies matching impersonation tactics
  • Assess personal device security awareness and potential impact
  • Investigate any reported data extortion attempts linked to this campaign

Why It Matters

This vishing campaign leverages social engineering to circumvent enterprise security controls by targeting employees’ personal devices, increasing the risk of unauthorized access to critical SaaS data.

Source