UNC6671 Vishing Campaign: What Pittsburgh SMBs Should Do Now

What happened
A threat group tracked as UNC6671 is running a fresh wave of voice-phishing (vishing) attacks aimed at employees at financial services, private equity, and professional services firms, according to reporting from feeds.feedburner.com. The attackers impersonate internal IT help desk staff and pressure workers into cooperating with what they frame as a mandatory, urgent "security migration."
Two details stand out from the write-up. First, the goal is data extortion built on stolen SaaS account access, not classic ransomware on endpoints. Second, the attackers are reaching employees on their personal phones, which sidesteps most of the corporate call-screening and email-security controls a business relies on. Additional tradecraft specifics beyond that are worth verifying directly against your own threat intel feed or your MSP's advisories before you brief staff.

Why this matters for Pittsburgh SMBs
If you are a 25-person CPA practice in the Strip, a 60-attorney firm downtown, a wealth management shop in Fox Chapel, or a specialty manufacturer in the Mon Valley with a defense contract, this campaign is aimed squarely at your industry profile. UNC6671's target list, financial services and professional services, maps almost one-to-one to the verticals we serve every day. These are also the industries where a single compromised Microsoft 365 or SaaS admin account can expose client tax records, privileged legal matters, PHI, or CUI in a matter of minutes.
Smaller organizations are especially exposed here for three reasons. One, your help desk is often a familiar voice, so a caller claiming to be "from IT" doesn't automatically feel wrong, especially if they name your actual MSP. Two, most SMB security programs are tuned for email-borne phishing and endpoint malware; a phone call to someone's personal cell is a blind spot. Three, if you are working toward SOC 2, FTC Safeguards, HIPAA, or CMMC Level 2 attestation, a successful vishing-driven account takeover is exactly the kind of incident that turns a clean audit into a reportable breach with 72-hour notification clocks.
The extortion angle also matters. Because UNC6671 is reportedly focused on stealing SaaS data rather than encrypting servers, you may not see the usual ransomware "tells" (mass file renames, EDR alerts, downed VMs). The first sign of trouble could be an extortion email referencing files your team didn't know had left the tenant.
What to do about it this week
None of these require a big project. Pick the ones you don't already have nailed down and get them moving before Labor Day.
- Publish a one-page "IT will never" notice. State plainly that your help desk (internal or your MSP) will never call an employee's personal cell to walk them through an urgent security migration, MFA reset, or credential re-enrollment. Post it in Teams, email it, and pin it. If a call like that happens, the employee hangs up and calls a known number.
- Move MFA off SMS and voice for admins. Enforce phishing-resistant methods (FIDO2 keys, Windows Hello, or number-matching in Authenticator) for every Global Admin, Exchange Admin, and SharePoint Admin in your Microsoft 365 tenant. Push the same to anyone with financial approval authority.
- Add a callback verification step for help-desk-initiated changes. Any password reset, MFA reset, or session revocation triggered by an inbound request should be verified through a second channel your IT provider controls, not the phone number the caller supplied.
- Turn on the M365 signals that catch post-vishing takeover. Review risky sign-ins, impossible travel, mailbox forwarding rules, OAuth app consents, and eDiscovery/Purview activity. If you have E5 or Business Premium, Microsoft Purview DLP alerts on large SharePoint/OneDrive downloads are cheap wins.
- Run a targeted tabletop. Ten minutes, four people (owner, ops lead, finance lead, IT contact). Scenario: "Someone called Sarah's cell claiming to be from IT and she gave them a code." Who does what in the first hour? Who calls the cyber insurer? Who preserves logs?
- Refresh your acceptable-use and personal-device language. Employees should know it is expected, not rude, to refuse an unknown caller asking about work systems. This is a good pairing with an acceptable-use policy refresh if you've been rolling out Copilot or other AI tools.
- Confirm your SaaS backup and audit-log retention. Microsoft's default log retention will not carry you through a slow-burn extortion investigation. Verify you have at least 180 days of unified audit log access and independent backups of Exchange, SharePoint, OneDrive, and Teams.

How we help
PGH Networks handles this stack end-to-end for SMBs across Western PA: hardened Microsoft 365 baselines and conditional access, 24x7 MDR with human-led response, managed IT and help-desk workflows built around verified callbacks, and vCIO guidance to line your controls up with HIPAA, SOC 2, FTC Safeguards, or CMMC before an auditor or a threat actor forces the issue. If UNC6671's playbook has you wondering how your team would actually respond at 4:45 on a Friday, let's pressure-test it together.
Talk to PGH Networks
Call us at 724.888.7007 or reach out through the contact form and we'll set up a 30-minute working session on your vishing exposure and M365 controls.
Related reading

WordPress Pre-Auth XSS Hits Every Version: Patch Your Site Now
A critical WordPress pre-auth XSS (CVE-2026-64638) affects every version and can chain to PHP code execution. Here is what Pittsburgh SMBs should do this week.

HollowFrame Loader Hits a Law Firm: What Pittsburgh SMBs Should Do
A new spear-phishing chain (HollowFrame loader, Matryoshka backdoor) hit a law firm. Here is what Pittsburgh SMBs should verify and fix this week.

Hijacked Hotel Wi-Fi Is Pushing Fake Browser Updates: SMB Advisory
Hijacked hotel Wi-Fi is pushing fake browser updates that install a webcam and keystroke RAT. What Pittsburgh SMBs should do this week to protect travelers.