A new wave of vishing attacks from UNC6671 targets personal phones, posing as IT help desk to steal SaaS credentials. Learn how to spot and stop this scam.
A new wave of cyber attacks is making the rounds, and it's not targeting your inbox or your work laptop. Instead, the bad guys are calling your personal cell phone, pretending to be your IT help desk, and trying to swipe your SaaS credentials. Security researchers have pinned this campaign on a data extortion group called UNC6671, and they're going after financial services, private equity, and professional services firms.
### Why Your Personal Phone Is Now a Target
Here's the thing that makes this so unsettling: these attackers aren't just calling your office line. They're reaching out to your personal number, which feels way more invasive. It's a tactic that's designed to catch you off guard, because when someone calls your personal device, you're less likely to be in "work defense mode." You're probably just expecting a call from a friend or maybe a delivery driver, not a hacker trying to trick you into handing over access to your company's most sensitive data.
UNC6671 has a pretty specific playbook. They pose as IT help desk staff, and they spin a story about a mandatory, urgent security migration. It sounds official. It sounds time-sensitive. And that's exactly what makes it so dangerous.
### The Psychology Behind the Attack
Let's break down why this works so well. When you get an urgent call at work, your brain kicks into problem-solving mode. But when you're at home, or out running errands, and your personal phone rings with someone claiming to be from your company's IT department, you're not in that same headspace. You're more relaxed, more trusting, and less likely to question things.
The attackers know this. They're banking on you being a little distracted, a little more eager to just get the issue resolved so you can get back to your day. They create a sense of urgency that makes you want to act fast, and they use the authority of the IT department to make you comply without thinking too hard.
### How to Protect Yourself and Your Company
So, what can you actually do about this? First, remember that no legitimate IT department is going to call you on your personal phone to demand urgent action on a security migration. That's not how real security teams operate. If you ever get a call like this, hang up and call your company's IT help desk directly using the number you have on file.
- Never give out passwords, one-time codes, or multi-factor authentication codes over the phone
- If someone asks you to install software or visit a website, that's a massive red flag
- Always verify the caller's identity through a separate, trusted channel
- Talk to your team about this tactic so everyone knows what to look out for
### A Quick Word on Staying Vigilant
This is a good reminder that cyber threats are always evolving. The attackers aren't just sitting in a basement sending out mass phishing emails anymore. They're doing their homework, they're picking up the phone, and they're getting personal. It's a little creepy, honestly, but being aware of the threat is half the battle.
If you work in financial services, private equity, or professional services, you're in the crosshairs. Take this seriously. Have a conversation with your security team about how they communicate with employees, and make sure everyone knows that urgent, unsolicited calls about security issues are almost always a scam.
### The Bottom Line
At the end of the day, the best defense is a healthy dose of skepticism. If something feels off, it probably is. Hang up, verify, and don't be afraid to be a little paranoid. Your company's data, and your own peace of mind, are worth it.