All posts

Attackers now spoof your IT helpdesk number to steal MFA tokens

Huma ShaziaAugust 8, 2026 at 11:47 PM4 min read
Attackers now spoof your IT helpdesk number to steal MFA tokens

The voice phishing attack targeting your finance team just got harder to spot. Google's Threat Intelligence Group revealed on August 6 that threat actor UNC6671 is now spoofing legitimate IT helpdesk phone numbers when calling employees, making social engineering attempts appear to come from inside the company. The group targets financial services, private equity, and professional services firms with calls to personal mobile devices, bypassing corporate security controls entirely.

Attackers now spoof your IT helpdesk number to steal MFA tokens
Source: PYMNTS |

The tactic is straightforward and effective. Attackers pose as IT support staff, claim there's an urgent security migration, and direct victims to spoofed login portals. Once the employee enters credentials and MFA tokens, automated scripts begin exfiltrating data from enterprise cloud environments. The caller ID shows the real helpdesk number.

Advertisements

What changed since May

How Hackers Bypass MFA to Steal Your Data via Session Token Theft

GTIG first documented UNC6671's tactics in May. The August update shows the group has refined its methods. Beyond spoofing helpdesk numbers, they've added defense evasion techniques to maintain persistence and hide their tracks.

In recent intrusions, the group used compromised email accounts to initiate unauthorized password resets for non-SSO enterprise applications. To prevent end-user detection or automated security alerts, operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations.

— Google Threat Intelligence Group

This means employees won't receive the usual warning signs. No password reset confirmation. No security alert. The first indication of compromise may be missing data.

The financial sector is the primary target

UNC6671 operates under multiple extortion brands. The goal is data theft, followed by extortion. Financial services firms handle sensitive transaction records, client information, and market data worth paying to protect. Private equity firms hold deal pipelines and portfolio company data. Professional services firms sit on privileged client communications.

$300 million
Estimated cost to MGM Resorts from a 2023 attack by related threat actors using identical vishing techniques

Google and Mandiant had already warned in June that data theft extortion groups were impersonating IT support to target these exact sectors. This August disclosure confirms the attacks are escalating, not slowing.

Advertisements

Why personal mobile phones matter

Corporate phone systems often have call screening, recording, or security integrations. Personal mobile phones have none of that. By calling employees directly, attackers bypass any corporate telephony controls. The employee sees a familiar helpdesk number, answers on their personal device, and has no corporate system flagging the call as suspicious.

The pretext is clever. UNC6671 callers claim the employee must urgently enable FIDO2 passkeys or update MFA enrollment. These are real security measures companies actually deploy. The urgency feels plausible. The request sounds like something IT would actually ask.

What finance teams should do now

The core problem is that employees cannot trust caller ID. IT departments need to establish verification protocols that don't rely on the phone number displayed. Some options: employees call back using a known number, use a separate verification channel like Slack, or require in-person verification for security changes.

ℹ️

Disclosure

Some links in this post are affiliate links — Logicity earns a commission if you sign up, at no extra cost to you. We only link products we have used or actively recommend.

Organizations should also audit which non-SSO applications are connected to corporate email. UNC6671 is using compromised email accounts to reset passwords on these apps. If the app doesn't use SSO, it's a vector. Cloud security monitoring through services like Cloudflare or native cloud provider tools should flag unusual bulk data access patterns.

ℹ️

Logicity's Take

The shift to personal mobile phones is the real news here. Most security awareness training assumes attackers reach employees through corporate channels. UNC6671 has found the gap: employees are conditioned to trust calls from the helpdesk, and caller ID spoofing is trivial. Financial services firms should assume their helpdesk numbers are compromised for phishing purposes and build verification workflows that don't depend on them.

The National Retail Federation reported separately that criminals are shifting from physical theft to phone scams. The pattern is consistent across industries: social engineering through voice calls scales better than traditional fraud, and current defenses aren't keeping pace.

ℹ️

Need Help Implementing This?

Need to build verification workflows for IT requests or audit your cloud security posture? Reach out to Logicity's consulting partners for enterprise security architecture support.

Source: PYMNTS | / PYMNTS

H

Huma Shazia

Senior AI & Tech Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.