Private-equity firms are among the latest targets of a financially motivated threat cluster tracked by Google Threat Intelligence Group (GTIG) as UNC6671. The operators previously used the BlackFile name and now present themselves as REDACT.
REDACT relies heavily on voice phishing, credential theft and access to cloud services. For private-equity firms, where a compromised identity may expose information spanning multiple investments and transactions, that approach creates a distinct risk.
Private Equity in the Crosshairs
News sites reported on 6 August that attackers had prepared phishing infrastructure targeting employees at several major private-equity firms. Other financial organizations have reportedly been targeted.
The evidence instead points to deliberate preparation. Attackers created infrastructure tailored to specific organizations as part of a wider campaign against the financial sector.
REDACT’s release page on the Dark Web does not identify the names of any organizations that have allegedly been affected as part of this campaign as confirmation at this time.
Extortion, Not Conventional Ransomware
Although BlackFile has sometimes appeared in ransomware discussions, REDACT is employing data-theft extortion rather than file-encrypting ransomware.
The operators have used voice phishing, or vishing, to impersonate corporate IT and help-desk personnel. Employees may receive calls directing them toward attacker-controlled authentication pages under the guise of an MFA, passkey or account-enrolment task.
The aim is to obtain a legitimate identity.
Once access is established, the attackers can move into cloud and SaaS environments and collect sensitive corporate information. GTIG has documented activity involving Microsoft 365, SharePoint and OneDrive, including scripted collection using Python and PowerShell.
Rather than encrypting systems, the operators steal data and use the threat of disclosure as leverage for payment.
That difference matters for defenders. Controls designed around detecting ransomware binaries or mass encryption may never encounter either.
From BlackFile to REDACT
BlackFile is no longer the name its operators use publicly.
During review of the group’s presence, the REDACT site remained accessible and contained a 22 May 2026 “Blackfile Operational Update.” The post states that operations under the BlackFile name had permanently ceased but that the operation itself was continuing under the REDACT name.
The site also provides a useful view into an ongoing attribution dispute.
On 7 August, REDACT published a response to recent Mandiant reporting. In that statement, the operators claimed that Falcon is their only affiliated group and explicitly denied affiliations with Helix and Pink.
REDACT says it shares no tooling, infrastructure, operators or negotiation channels with those two groups.
The operators offer their own explanation for similarities identified by researchers. They claim former affiliates removed from their operation subsequently established separate groups and copied REDACT’s infrastructure and tactics, techniques and procedures.
REDACT’s statement provides a hypothesis for the technical overlap seen with Falcon, Pink and Helix.
One Cluster, Several Names
GTIG continues to track the underlying intrusion activity as UNC6671.
Cybercrime operations can include affiliates, contractors and infrastructure providers whose relationships change over time. Former members may also retain knowledge of tooling and tradecraft.
REDACT itself claims that expelled affiliates never had access to its victim data and would therefore be unable to re-extort previous victims. That statement is unverified, but it raises an interesting question about the group’s structure: victim data may be more centrally controlled than in some traditional ransomware-as-a-service models.
Why Private Equity Fits the Model
Private equity firms hold an unusually valuable concentration of information.
Deal pipelines, acquisition targets, portfolio-company data, investor communications, financing arrangements and due-diligence material can all carry substantial commercial sensitivity.
An attacker who compromises the right cloud identity may therefore gain access to information extending well beyond one organization.
REDACT’s activity is a reminder that the threat does not need to begin with a sophisticated exploit. It can begin with a convincing phone call and a legitimate-looking authentication page.
Protecting Against Identity-Led Extortion
Organizations that have invested in MDR benefit from 24/7 monitoring across identity, endpoint and cloud environments for indication of compromise associated with credential theft, suspicious authentication and abnormal data access.
For campaigns that utilize stolen credentials and cloud access as a central part of the intrusion, continuous monitoring gives security teams the ability to identify and contain the threat before significant exfiltration occurs.
When suspicious activity is identified, rapid response and triage contain the intrusion, taking action to contain affected accounts and systems.