// Microsoft 365HIGH
UNC6671, operating under aliases Redact, Pink, Falcon, and Helix, conducted a sustained phishing campaign targeting over 200 financial services firms and enterprises. Attackers posed as IT help desk staff via phone calls to employees' personal numbers, directing victims to fake credential-harvesting websites mimicking company SSO portals to steal usernames, passwords, and MFA codes. Once compromised, attackers deleted security alerts and password reset notifications to hide their presence. Targets included major firms such as Blackstone, Bridgewater Associates, Apollo Global Management, KKR, and CME Group.
- Hackers Impersonate IT Support to Breach Leading Financial Compa(opens in a new tab)
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain (opens in a new tab)
// Get alerts for Microsoft 365