CTIPilot

Okta

product · product:okta

Coverage timeline
2
first 2026-07-18 → last 2026-08-07
Peak priority
high
1 high · 1 notable
Sources cited
8
5 hosts
Sections touched
2
active-threats, deep-dive
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
14
pinned v19.2 · see below

ATT&CK techniques

14 techniques observed across 2 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1598.004Phishing for Information: Spearphishing Voice×2

Adversaries may use voice communications to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×2

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×2

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗

Stealth TA0005

T1070.008Indicator Removal: Clear Mailbox Data×1

Adversaries may modify mail and mail application data to remove evidence of their activity. Email applications allow users and other programs to export and delete mailbox data via command line tools or use of APIs. Mail application data can be emails, email metadata, or logs generated by the application or operating system, such as export requests.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

T1684.001Social Engineering: Impersonation×1

Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗

Defense Impairment TA0112

T1556.006Modify Authentication Process: Multi-Factor Authentication×2

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

Credential Access TA0006

T1556.006Modify Authentication Process: Multi-Factor Authentication×2

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗

T1621Multi-Factor Authentication Request Generation×1

Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗

Collection TA0009

T1114.002Email Collection: Remote Email Collection×1

Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗

T1213.002Data from Information Repositories: Sharepoint×2

Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · ATT&CK page ↗

T1530Data from Cloud Storage×2
T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗

Command and Control TA0011

T1090.002Proxy: External Proxy×1

Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗

Impact TA0040

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm · ATT&CK page ↗

Story timeline

  1. 2026-08-07UNC6671 kept operating after BlackFile's announced retirement, across four further extortion brands, and its vishing pretext is now an urgent order to enroll a FIDO2 passkey
    deep-diveThe group behind BlackFile never stopped: GTIG ties four newer extortion brands to one operator whose lure attacks passkey enrolment, not the passkey
  2. 2026-07-18Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records
    active-threatsAbbott confirms unauthorized access to its Cancer Diagnostics (Exact Sciences) systems as ShinyHunters claims a helpdesk-vishing to Entra SSO breach

Where this entity is cited

  • active-threats1
  • deep-dive1

Source distribution

  • bleepingcomputer.com4 (50%)
  • abbott.com1 (12%)
  • cloud.google.com1 (12%)
  • health-isac.org1 (12%)
  • medtechdive.com1 (12%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Okta (2)

2026-08-07 · view entry permalink →

HIGHNATOB2

UNC6671 kept operating after BlackFile's announced retirement, across four further extortion brands, and its vishing pretext is now an urgent order to enroll a FIDO2 passkey

The retirement of a ransomware brand is a press release, not an outcome. Google Threat Intelligence Group reports that UNC6671, the actor behind the BlackFile extortion brand whose shutdown was announced in May 2026, went on operating and diversified across four further extortion fronts (Redact, Pink, Helix and Falcon) with the intrusion tradecraft essentially untouched (GTIG / Mandiant, 2026-08-06). The linkage is an assessment rather than a certainty, and GTIG says so: overlapping victim targeting across brands "support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible" (GTIG / Mandiant, 2026-08-06). The evidentiary basis is infrastructure economics: rather than isolating infrastructure per victim, the operator reuses generic root domains across many targets and appends victim-name subdomains, so one root domain used against a Falcon-extorted organisation was simultaneously used against a Helix-extorted one, and the same phishing templates, identical in code and design, were served from several of those domains at once.

The lure is the important change, and it inverts the standard advice. The pretext is an urgent helpdesk mandate to enable FIDO2 passkeys or update MFA enrolment, delivered by a caller who reaches the employee on their personal mobile; GTIG records that "UNC6671 callers have continued to call targeted employees on their personal mobile numbers, circumventing corporate security controls", and that "in at least some recent cases, the threat actor has spoofed the legitimate helpdesk phone number adding an air of legitimacy" (GTIG / Mandiant, 2026-08-06). Root domains pair authentication vocabulary (passkey, mfa, sso) with a verb, so the destination reads as an enrolment portal. GTIG's own hardening guidance names phishing-resistant authenticators as the durable control, because "these authenticators implement WebAuthn standard to enforce cryptographic origin binding between the authenticator and the specific domains it can authenticate to, rendering lookalike domains and AiTM proxies ineffective" (GTIG / Mandiant, 2026-08-06). The operational catch is that origin binding protects an authenticator that already exists; this actor attacks the moment one is created. A defender who has deployed passkeys and considers the identity problem closed has hardened the authentication step and left the enrolment step as the way in.

Post-compromise, the chain is deliberately quiet. With session persistence established, the operator uses compromised mailboxes to trigger password resets on non-SSO enterprise applications, then blinds the victim: GTIG records that "operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations" (GTIG / Mandiant, 2026-08-06). Exfiltration is scripted rather than hands-on-keyboard, pulling data from Microsoft 365 and other SaaS stores at machine rates. GTIG characterises the operation as data-theft extortion throughout and no cited source describes an encryption stage; the leverage on the evidence published is publication.

Targeting has moved deliberately upmarket. Between April and May 2026 the domains were aimed broadly at large enterprises in manufacturing, real estate, healthcare and insurance; in June the focus shifted to technology, transportation and hospitality; and "by July 2026, the target profile narrowed to focus on the financial and legal sectors, with observed infrastructure directed at private equity firms, law firms, and financial rating agencies" (GTIG / Mandiant, 2026-08-06), organisations holding merger, capital-deployment and litigation material, which is leverage rather than data. Operational tempo rose with it, to "an accelerated cadence of approximately one domain every 1.6 days" across June and July against one every 2.2 days in the preceding two months (GTIG / Mandiant, 2026-08-06). BleepingComputer, relaying Reuters and Bloomberg, reports that recent targets in this financial-sector phase include several large US hedge funds and private-equity firms; GTIG names no victims itself (BleepingComputer, 2026-08-06).

The economics explain why announced retirements mean nothing. GTIG reviewed 18 BlackFile Bitcoin wallet addresses receiving 141.65 BTC (roughly $10.69 million at transaction time) between 2026-01-07 and 2026-05-12, with payments continuing past the 2026-05-11 shutdown notice and significant cash-out events in late April and early May. Initial demands run from $1 million to upwards of $3 million, negotiated down by 50% to 75%, and "in over 53% of tracked cases in this timeframe, final payments averaged $750,000 USD (~10.2 BTC)" (GTIG / Mandiant, 2026-08-06). GTIG's read is that the multi-brand structure most likely compartmentalises operations, hides total breach volume and isolates negotiation fallout, which is why brand-based tracking misleads and TTP-based tracking does not.

These overlaps support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible.

UNC6671 callers have continued to call targeted employees on their personal mobile numbers, circumventing corporate security controls.

In at least some recent cases, the threat actor has spoofed the legitimate helpdesk phone number adding an air of legitimacy.

operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations.

In over 53% of tracked cases in this timeframe, final payments averaged $750,000 USD (~10.2 BTC).

These authenticators implement WebAuthn standard to enforce cryptographic origin binding between the authenticator and the specific domains it can authenticate to, rendering lookalike domains and AiTM proxies ineffective.

Google Threat Intelligence Group / Mandiant 2026-08-06
threat07 Aug 04:41Zmulti-sourceOpen finding ↗

2026-07-18 · view entry permalink →

NOTABLEupdatedNATOA3

Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records

Abbott Laboratories is investigating a cyber incident and states there was "unauthorized access to a limited number of internal systems in our Cancer Diagnostics business only," adding that there is "no impact to any other Abbott businesses, sites or systems" and that the legacy Exact Sciences systems (Exact Sciences was folded into Abbott's diagnostics business in a 2026 acquisition) remain separate from Abbott's core infrastructure (Abbott, 2026-07-16). Abbott has not named an actor, confirmed a method, or disclosed what kind of information was accessed (MedTech Dive, 2026-07-17).

The ShinyHunters extortion group (registry-tracked, alias UNC6240) claims responsibility, saying the intrusion began with a vishing (voice-phishing) attack targeting several Abbott employees that compromised a Microsoft Entra ID single-sign-on account, which was then used to "exfiltrate data from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa", the actor's leak-site posting claims more than 30 million customer records, medical notes and orders, and set a leak deadline it later pushed to 21 July (BleepingComputer, 2026-07-17). A second, separate claim by an actor calling itself "ShadowByt3\$" alleges compromise of an externally facing LabCentral portal, which BleepingComputer reports houses publicly available technical product reference documents and does not contain proprietary or sensitive customer or business information (BleepingComputer, 2026-07-17). The record counts and the specific SaaS platforms are the actor's unverified claim, not Abbott's confirmation.

Abbott is investigating a cyber incident in which there was unauthorized access to a limited number of internal systems in our Cancer Diagnostics business only.

Abbott Laboratories (own statement) 2026-07-16

ShinyHunters claimed it exfiltrated data from Microsoft Entra, ServiceNow, SharePoint, Databricks, and Coupa, including internal documents, contracts, and customer information.

BleepingComputer 2026-07-17

SSO is the control plane, and ShinyHunters' leverage is created through data theft at cloud scale.

Health-ISAC 2026-07-24

The advisory does not identify affected healthcare organizations, disclose how many incidents have been observed, or provide a timeframe for the reported increase.

The intrusion did not impact in any way the company's alarm monitoring and system functionality.

BleepingComputer 2026-07-17
Updaterun 2026-07-31T0409Z-intelaffected_productsentitiesevidenceregionssectorssourcestagstechniquesbody

Prior coverage tracked this actor's vishing-to-Entra-SSO tradecraft through the Abbott and Ernst & Young incidents as individual cases. The delta is that a sector body has now written the chain down as a pattern with a mitigation timeline attached, and that a fresh confirmed intrusion shows the same entry point (BleepingComputer, 2026-07-29).

Health-ISAC's advisory describes the chain end to end: voice phishing directed at helpdesk staff, leading to a password reset, MFA reset or device re-enrolment carried out without out-of-band identity proofing, giving the caller a legitimate Entra, Okta or Google SSO session; from there the operators pivot into the connected SaaS estate (Salesforce, Microsoft 365, SharePoint, ServiceNow, Teams) and exfiltrate in bulk. There is no encryption stage; the stolen data is the entire extortion instrument. Its own summary of why this works is the line worth quoting to a steering committee: SSO is the control plane, and the leverage comes from data theft at cloud scale. It recommends treating Entra, Okta and equivalent identity infrastructure as Tier 0, locked down the way a domain controller is, with a 30-to-60-day action list covering phishing-resistant MFA for high-risk users, hardened helpdesk reset procedures with verified callback, a conditional-access baseline blocking legacy authentication, SaaS-exfiltration detection on bulk downloads, API anomalies and OAuth-consent changes, and a tested token- and session-revocation playbook (Health-ISAC, 2026-07-24).

Two things about how the advisory is written are as informative as its content. It names no victims at all; BleepingComputer states directly that it does not identify affected organisations, disclose how many incidents have been observed, or give a timeframe for the increase, and the medtech and healthcare companies frequently listed alongside it come from BleepingComputer's own earlier reporting rather than from the advisory. And Health-ISAC cautions that not every data-theft claim has been verified, directing defenders at the attack pattern rather than at any specific tally. For a sector body facing an actor whose business model is publicising claims, declining to repeat the claims is a deliberate and defensible choice.

The fresh case landed the following day. Brinks Home confirmed, through its chief executive, that it detected an intrusion on 2026-07-20, engaged forensic experts, and that the intrusion did not affect its alarm monitoring or system functionality in any way; its own incident FAQ says it has not yet confirmed exactly what information was involved or whose (BleepingComputer, 2026-07-30). ShinyHunters claims the breach began on 13 July with a call convincing an employee to complete a Microsoft Entra authentication or registration process, and claims specific volumes of Salesforce, employee and support-chat data; BleepingComputer reports two different Salesforce record counts in the same article without reconciling them, and states it has not reviewed the data and could not verify the claims. The mechanism the actor describes matches the pattern the advisory documents, which is the reason to note it; the numbers are not established and are not treated here as though they were.

Detection. Everything useful sits in identity telemetry, and the shape is a sequence rather than an event. The trigger is a helpdesk-initiated credential or authenticator change, a password reset, an MFA method reset, or a new device registered against an existing account. What turns it into an incident is what follows within minutes to hours: a first successful sign-in for that account from a device, network or geography with no history, then enumeration and bulk retrieval against connected SaaS applications; large report exports, unusual API query volume against customer-record objects, new OAuth consent grants. Instrument the join between the reset event and the next sign-in, because either half alone is ordinary.

Triage: a locked-out user calling the helpdesk and having their MFA reset is one of the most common legitimate identity events in any organisation, and it looks identical to this attack up to the moment the reset completes. The discriminator is not in the endpoint or the network; it is whether identity was proven out of band, by a callback to a number already on record rather than a number the caller supplied, and whether the sign-in that follows the reset comes from anywhere the account has been before. Where the helpdesk's own process logs that verification step, the absence of it on a given ticket is the highest-fidelity signal available.

incident18 Jul 04:35Zmulti-sourceOpen finding ↗