Advanced Vishing Attacks on Enterprise Devices

A data extortion group known as UNC6671 is using voice phishing (vishing) to target financial services, private equity, and professional services firms, with a new tactic of attacking personal phones to steal SaaS data.

Recently, a series of sophisticated attacks have been reported, targeting financial services, private equity, and professional services firms. The attacks are attributed to a data extortion group known as UNC6671. This group has been known to use voice phishing (vishing) to target enterprise employees, posing as IT help desk staff, and requesting sensitive information. In a recent twist, UNC6671 has shifted its tactics to focus on personal phones, using vishing attacks to steal sensitive data from SaaS applications.

The attacks involve sending targeted phone calls to unsuspecting victims, often claiming to be from the IT department of the company. The attackers then use psychological manipulation to extract sensitive information, such as login credentials and SaaS data, from the victims.

Experts warn that these attacks are particularly effective because they exploit the trust that employees have in their IT departments. By posing as IT staff, the attackers are able to bypass traditional security measures and gain access to sensitive information.

Source: The Hacker News