Redact — Ransomware Profile

Redact is a data-theft extortion operation and dark-web leak site that surfaced in May 2026 as a rebrand of the BlackFile extortion brand, activity that vendors track as UNC6671, CL-CRI-1116 and Cordial Spider and associate with the English-speaking cybercriminal network The Com. The group does not deploy an encryptor; it gains initial access through voice-phishing calls impersonating corporate IT help desks, harvests credentials and MFA codes via adversary-in-the-middle single sign-on pages, registers rogue MFA devices for persistence, and mass-exfiltrates data from cloud services including Microsoft 365, SharePoint, OneDrive and Salesforce using API-based tooling such as Microsoft Graph scripts. Victims receive seven-figure ransom demands on 72-hour deadlines, with pressure tactics that have included threatening calls to executives, email-flooding spam campaigns and swatting of employees. The Redact leak site has listed two US victims to date, Hologic and FCCI Insurance Group, both posted in late June 2026; neither intrusion has been publicly confirmed, and Hologic had previously been claimed by the unrelated 0apt group in February 2026. Google Threat Intelligence attributes Redact to UNC6671 but notes the rebrand may reflect a rogue affiliate operating the brand rather than the original BlackFile core.

Also tracked as

BlackFile, UNC6671, CL-CRI-1116, Cordial Spider

IntelFusions coverage (4)

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions