Vanishing Act: What Really Happened to BlackFile?
Austin Larsen
In early 2026, the extortion brand "BlackFile" (UNC6671) quietly became one of the most impactful and under-reported threat actors of the year. Targeting dozens of organizations and making millions in the process, they used live AiTM vishing to bypass MFA, blinded SOCs through API manipulation, and leveraged extreme escalation tactics like corporate swatting. But the real story is their chaotic disappearance and bizarre resurrection. In early May, BlackFile operators vanished mid-negotiation, dropping offline completely. Days later, they allegedly returned with a new leak site dubbed "Redact." This supposed rebrand is full of red flags. They abandoned their own communication protocols to mimic the playbook of ShinyHunters, advertising a "primary" Tox ID and directly addressing negotiation firms. Was BlackFile scared into retirement? Did another actor take over the group? Is this just another rebrand? This 10-minute session takes you inside the GTIG investigation into UNC6671, revealing their stealthy AiTM mechanics, the aggressive realities of their extortion, and how underground drama can derail a multi-million dollar cybercrime empire.