BlackFile Explained

How vishing and SSO compromise lead to mass data theft.

by Gene Reich

August 10, 2026

Assume the break, design for the blast radius

Ask most security teams how a breach starts and you will hear about prevention. That work matters, but it has a ceiling, because given enough time, someone eventually gets in. The strongest programs plan for that, and what they plan for is reach. Once an attacker is inside with a working identity, how far it can take them decides the cost.

BlackFile shows how far that can go. Google Threat Intelligence Group tracks the 2026 extortion operation as UNC6671, and by their count it reached dozens of organizations across North America, Australia, and the UK without exploiting a single software flaw. The way in was social engineering, so no patch and no perimeter would have changed the outcome. The leak site went dark in April 2026 and the group announced it was "shutting down... under this name," which GTIG reads as a rebrand, not a retirement. The brand is disposable. The method still works.

BlackFile Deletion Process after Social Engineering

How one foothold became total reach

The method starts with a phone call. A caller posing as internal IT, often reaching employees on their personal phones, says a passkey migration or MFA update is due and sends them to a login page that looks like their own. As the employee types, the attacker relays each credential to the real provider and passes the live MFA prompt straight back. Then, to keep the access, the attacker registers their own MFA device, a standing authorized factor that no password reset will close.

From there, one trusted identity was enough. Through single sign-on it opened Microsoft 365, Okta, and the services behind them: SharePoint, OneDrive, Zendesk, Salesforce. The attackers searched for terms like "confidential" and "SSN," then scripted the exfiltration, reusing session cookies from the call and pulling files through legitimate APIs so the traffic logged as routine access, not a download. In one case that moved more than a million files from a single victim. None of it required breaking in. It required being let in once.

Prevention lowers the odds, not the blast radius

If being let in once is the problem, the obvious fix is to stop it. GTIG's first recommendation is phishing-resistant MFA, the FIDO2 keys and passkeys that break the relay outright, because there is no code for a caller to talk an employee into reading back. But be precise about what that fixes. It governs entry. It makes the first break less likely and says nothing about what happens after one, and the relay is only one way in. Convince the right person, find a forgotten account, or buy a working credential, and the attacker is inside with the same trusted identity and the same reach. When one identity is trusted across the whole estate, and sensitive data sits everywhere it can reach, a single failure exposes all of it.

Persistence is the multiplier

With BlackFile, all of it meant nearly everything the business had written down: contracts and NDAs, HR files, executive inboxes, full customer exports from Salesforce and Zendesk, the corporate directory, even IT asset records. None of that was unusual. It is the normal state of a mature company, where data accumulates and rarely leaves, reachable by the same logins because nothing ever told it to go away. So one trusted identity does not find a slice of the business. It finds everything that was never cleared out. The stolen identity was only the key. What made the extortion work was the pile it unlocked, the standing pool the attacker had searched by name on the way in.

Containment starts at the communication layer

If reach is what does the damage, the way to limit it is to leave less within reach. A compromised identity can only take what is still there. The communication layer is where to start, both one of the richest pools and the one BlackFile drew from directly: executive inboxes, Zendesk tickets, chat threads, full of content never meant to sit there permanently. This is the problem Traceless is built to remove. Instead of letting sensitive messages and files settle into tickets and inboxes, it moves them through one-time links that expire on a schedule, from thirty minutes to seven days, and vanish once viewed. The request that moves the data is tied to a verified identity, with every verification and retrieval logged. It covers tickets, chat, and email, not the document libraries and databases where data also piles up, and it complements existing identity controls rather than replacing them.

Designing for a smaller blast radius

The same logic scales to the whole estate, which can be designed for a smaller blast radius, not just defended against entry. Three levers do the work. First, the data: anywhere sensitive material sits idle, a single identity can carry it off, so treating standing data as a liability shrinks the prize before an attacker arrives. Second, reach: BlackFile's damage came from one identity that unlocked everything through single sign-on, so segmenting trust turns a total compromise into a partial one. Third, visibility: BlackFile was never invisible. The exfiltration was logged the whole time, just as ordinary file access, the attacker's client spoofed to look like Microsoft Office while the requests came from a Python script. Exchanges that are verified, expiring, and logged on purpose remove that ambiguity. A posture, not a product.

Survivability is the standard

The attackers have already adopted the mirror image of this. BlackFile did not break the system. It followed the paths employees use every day, a help desk call, a login, a file request, and turned ordinary workflow into the attack itself. Defenses built only to keep intruders out have little to say about a threat that arrives through the front door wearing a badge. Prevention still matters, and phishing-resistant MFA is the right first move, but it can only lower the odds of that first break, never erase them. Everything that decides the outcome afterward assumes the attacker gets in. That is the real lesson of BlackFile. The dangerous moment is not when the perimeter is breached. It is the moment after trust is granted, when a single identity becomes everything it can reach.

Prevent social engineering attacks

Start with one integration, validate quickly, and expand across your environment.