// OktaHIGH
Google's Threat Intelligence Group is tracking UNC6671, a cybercrime group conducting voice phishing attacks to hijack Okta accounts and exfiltrate corporate data for extortion. Attackers impersonate internal IT helpdesk staff, directing victims to adversary-in-the-middle phishing sites that capture credentials and MFA tokens. Since July 2026, the group has prioritized financial services, private equity, law firms, and rating agencies. Multiple campaigns share infrastructure under brand names including Falcon, Helix, Pink, and Redact.
- Weekly Cybersecurity Newsletter — Top 50 Cybersecurity Stories o(opens in a new tab)
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain (opens in a new tab)
// Get alerts for Okta