← Back to blog

UNC6671 Vishing Campaigns Target Enterprise SaaS Credentials

Threat group UNC6671 uses voice phishing to impersonate IT support and steal SaaS login credentials from enterprise employees. The attacks primarily impact financial services, private equity, and professional services firms.

TL;DR

  • UNC6671 is using vishing to target enterprise employees' personal phones
  • Attackers pose as IT help desk staff pushing 'urgent security migrations'
  • Primary targets include financial services, private equity, and professional services
  • Goal is to steal SaaS application credentials for data extortion
  • Organizations should implement call verification procedures for IT requests

A sophisticated threat actor tracked as UNC6671 has been conducting targeted voice phishing campaigns against enterprise organizations. The group specializes in calling employees on personal phones, masquerading as internal IT support to gain access to sensitive SaaS applications.

These social engineering attacks are particularly dangerous because they bypass traditional email-based security controls and exploit the trust employees place in legitimate-sounding technical support calls. UNC6671's primary objective appears to be harvesting credentials that provide access to valuable corporate data assets.

Attack Methodology

  • UNC6671 initiates contact via personal phone numbers rather than corporate lines
  • Attackers convincingly impersonate IT help desk personnel
  • Social engineering pretext involves urgent mandatory security migrations
  • Victims are manipulated into providing SaaS application login credentials
  • Calls are timed to create urgency and discourage verification procedures

Target Profile and Impact

  • Primary targets include financial services, private equity, and professional services firms
  • Focus on stealing credentials to business-critical SaaS applications
  • Access enables data theft for potential extortion purposes
  • Personal device targeting circumvents corporate network security measures
  • Compromised credentials can lead to persistent unauthorized access

Defensive Recommendations

  • Implement call-back verification procedures for all IT support requests
  • Educate employees about verifying caller identity through official channels
  • Establish clear protocols for credential-related requests over phone
  • Monitor for unusual authentication activity following suspicious calls
  • Consider implementing multi-factor authentication for all SaaS applications

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

UNC6671 Vishing Campaigns Target Enterprise SaaS Credentials — Agent Breach Blog | Agent Breach