Redact — Ransomware Profile
Redact is a data-theft extortion operation and dark-web leak site that surfaced in May 2026 as a rebrand of the BlackFile extortion brand, activity that vendors track as UNC6671, CL-CRI-1116 and Cordial Spider and associate with the English-speaking cybercriminal network The Com. The group does not deploy an encryptor; it gains initial access through voice-phishing calls impersonating corporate IT help desks, harvests credentials and MFA codes via adversary-in-the-middle single sign-on pages, registers rogue MFA devices for persistence, and mass-exfiltrates data from cloud services including Microsoft 365, SharePoint, OneDrive and Salesforce using API-based tooling such as Microsoft Graph scripts. Victims receive seven-figure ransom demands on 72-hour deadlines, with pressure tactics that have included threatening calls to executives, email-flooding spam campaigns and swatting of employees. The Redact leak site has listed two US victims to date, Hologic and FCCI Insurance Group, both posted in late June 2026; neither intrusion has been publicly confirmed, and Hologic had previously been claimed by the unrelated 0apt group in February 2026. Google Threat Intelligence attributes Redact to UNC6671 but notes the rebrand may reflect a rogue affiliate operating the brand rather than the original BlackFile core.Also tracked as
BlackFile, UNC6671, CL-CRI-1116, Cordial Spider
IntelFusions coverage (4)
- Encrypted AI thoughts leaked keys from public logs 2026-08-20 · AI Security
- Extortion crew hides behind five brands, Google says 2026-08-06 · Ransomware
- Attackers weaponize most public exploits within 48 hours 2026-08-03 · Vulnerabilities
- Newer ransomware crews claim diagnostics maker Hologic and an Australian fire service 2026-06-28 · Ransomware
Recent claimed victims
- Hologic 2026-06-28
- FCCI Insurance Group 2026-06-28
Vendor research
- GTIG's report Google Threat Intelligence