// Alert

Microsoft 365 threat report

UNC6671, operating under aliases Redact, Pink, Falcon, and Helix, conducted a sustained phishing campaign targeting over 200 financial services firms and enterprises. Attackers posed as IT help desk staff via phone calls to employees' personal numbers, directing victims to fake credential-harvesting websites mimicking company SSO portals to steal usernames, passwords, and MFA codes. Once compromised, attackers deleted security alerts and password reset notifications to hide their presence. Targets included major firms such as Blackstone, Bridgewater Associates, Apollo Global Management, KKR, and CME Group.

// Get alerts for Microsoft 365