Listen to the episode
TLDR
Cybercriminals linked to the BlackFile extortion group are calling employees on their personal mobile phones, spoofing the corporate IT helpdesk, and asking them to enroll in passkeys or update multi factor authentication settings. Victims...
How it works
Cybercriminals linked to the BlackFile extortion group are calling employees on their personal mobile phones, spoofing the corporate IT helpdesk, and asking them to enroll in passkeys or update multi factor authentication settings. Victims...
Red flags
- Unexpected call from "IT" on your personal mobile asking you to install software or change MFA settings. You are rushed through a multi step login that ends on a URL that does not exactly match your company's real domain. Security or password reset emails disappear from your inbox without your action
What to do
- 1Hang up and call your IT helpdesk back on a number published in the corporate directory. Never approve MFA prompts or install remote tools driven by an inbound
Source
bleepingcomputer
Source reviewed by Mythos Forensic Team
https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/FAQ
Is Helpdesk vishing scam steals SSO credentials from finance sector employees a real scam pattern?
Yes. Treat the message, call, or payment request as suspicious until you verify it through an official channel.
What are the first warning signs?
Unexpected call from "IT" on your personal mobile asking you to install software or change MFA settings. You are rushed through a multi step login that ends on a URL that does not exactly match your company's real domain. Security or password reset emails disappear from your inbox without your action
What should I do first?
Hang up and call your IT helpdesk back on a number published in the corporate directory. Never approve MFA prompts or install remote tools driven by an inbound
Can LegalAudit check my case?
Yes. Start a free chat and paste the message, link, sender, or payment details for triage.