The voice phishing attack targeting your finance team just got harder to spot. Google's Threat Intelligence Group revealed on August 6 that threat actor UNC6671 is now spoofing legitimate IT helpdesk phone numbers when calling employees, making social engineering attempts appear to come from inside the company. The group targets financial services, private equity, and professional services firms with calls to personal mobile devices, bypassing corporate security controls entirely.

The tactic is straightforward and effective. Attackers pose as IT support staff, claim there's an urgent security migration, and direct victims to spoofed login portals. Once the employee enters credentials and MFA tokens, automated scripts begin exfiltrating data from enterprise cloud environments. The caller ID shows the real helpdesk number.
What changed since May
How Hackers Bypass MFA to Steal Your Data via Session Token Theft
GTIG first documented UNC6671's tactics in May. The August update shows the group has refined its methods. Beyond spoofing helpdesk numbers, they've added defense evasion techniques to maintain persistence and hide their tracks.
“In recent intrusions, the group used compromised email accounts to initiate unauthorized password resets for non-SSO enterprise applications. To prevent end-user detection or automated security alerts, operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations.”
— Google Threat Intelligence Group
This means employees won't receive the usual warning signs. No password reset confirmation. No security alert. The first indication of compromise may be missing data.
The financial sector is the primary target
UNC6671 operates under multiple extortion brands. The goal is data theft, followed by extortion. Financial services firms handle sensitive transaction records, client information, and market data worth paying to protect. Private equity firms hold deal pipelines and portfolio company data. Professional services firms sit on privileged client communications.
Google and Mandiant had already warned in June that data theft extortion groups were impersonating IT support to target these exact sectors. This August disclosure confirms the attacks are escalating, not slowing.
Why personal mobile phones matter
Corporate phone systems often have call screening, recording, or security integrations. Personal mobile phones have none of that. By calling employees directly, attackers bypass any corporate telephony controls. The employee sees a familiar helpdesk number, answers on their personal device, and has no corporate system flagging the call as suspicious.
The pretext is clever. UNC6671 callers claim the employee must urgently enable FIDO2 passkeys or update MFA enrollment. These are real security measures companies actually deploy. The urgency feels plausible. The request sounds like something IT would actually ask.
What finance teams should do now
The core problem is that employees cannot trust caller ID. IT departments need to establish verification protocols that don't rely on the phone number displayed. Some options: employees call back using a known number, use a separate verification channel like Slack, or require in-person verification for security changes.
Disclosure
Some links in this post are affiliate links — Logicity earns a commission if you sign up, at no extra cost to you. We only link products we have used or actively recommend.
Organizations should also audit which non-SSO applications are connected to corporate email. UNC6671 is using compromised email accounts to reset passwords on these apps. If the app doesn't use SSO, it's a vector. Cloud security monitoring through services like Cloudflare or native cloud provider tools should flag unusual bulk data access patterns.
Logicity's Take
The shift to personal mobile phones is the real news here. Most security awareness training assumes attackers reach employees through corporate channels. UNC6671 has found the gap: employees are conditioned to trust calls from the helpdesk, and caller ID spoofing is trivial. Financial services firms should assume their helpdesk numbers are compromised for phishing purposes and build verification workflows that don't depend on them.
The National Retail Federation reported separately that criminals are shifting from physical theft to phone scams. The pattern is consistent across industries: social engineering through voice calls scales better than traditional fraud, and current defenses aren't keeping pace.
Need Help Implementing This?
Need to build verification workflows for IT requests or audit your cloud security posture? Reach out to Logicity's consulting partners for enterprise security architecture support.
Source: PYMNTS | / PYMNTS
Huma Shazia
Senior AI & Tech Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.






