Saudi Data Sales Converge With UNC6671 Extortion

Events tracked
223
Critical exposure
52

Summary

Coordinated data-sale claims against regulated financial entities coincided with a mature extortion operation splitting across multiple brands. The pattern elevates identity compromise and vishing above raw incident volume, while exposed industrial control systems keep operational technology risk in the foreground.

Today's developments

A significant cluster of alleged data sales emerged today, all attributed to the actor "Exchange Markets" and all targeting Saudi Arabian financial and government entities. The claims include breaches of the Capital Market Authority, Investor Protection, Tadawul, and Saudi National Bank. If substantiated, this represents a coordinated campaign against the Kingdom's financial regulatory and banking infrastructure. Separately, an actor known as "osito" claims to have breached a Saudi hospital and the insurance firm SAICO, extending the targeting into the healthcare and insurance verticals. These incidents, while unverified, suggest a deliberate focus on Saudi Arabia's financial ecosystem.

Beyond the Middle East, a wide range of alleged breaches and leaks were reported globally. The actor "exfilar" claims to have breached three U.S. transportation and insurance firms: American Auto Shipping, Cruise Control Auto Transport, and Allstate Tax LLC. In Europe, "omni777" claims breaches of French IT services firm Questel SAS and Swiss healthcare giant Alcon Inc. Educational institutions were also targeted, with claims against Universidad Adolfo Ibáñez in Chile, Universidad CNCI in Mexico, and multiple Uruguayan education bodies. The actor "LaPampaLeaks" claims breaches of Uruguay's CEIP and GURI systems, while "malconguerra2" claims a breach of Venezuela's SAIME identity agency. These incidents highlight the continued global dispersion of data breach activity across sectors and geographies.

Industry research published today provides critical context for these events. Google Threat Intelligence released a detailed analysis of UNC6671, a threat actor that has allegedly rebranded from BlackFile into four separate extortion fronts: Redact, Pink, Helix, and Falcon. The group reportedly continues to rely on vishing campaigns, impersonating IT helpdesk staff to harvest credentials and MFA tokens. The analysis notes a shift in targeting toward financial services, private equity, and legal firms, with initial ransom demands ranging from $1 million to $3 million. Separately, researchers at Forescout identified over 4,400 internet-exposed Rockwell PLCs, including 22 in cities recently targeted by water system attacks. Cisco also patched 12 SD-WAN and IOS XE vulnerabilities, three of which carry a CVSS score of 9.9, and a new KVM flaw dubbed "Zapscape" (CVE-2026-64561) could allow guest-to-host escapes in virtualized environments.

Threat landscape signals

The event set shows a notable concentration of activity from a small number of prolific actors. "azraelzer0d4y" leads with 12 events, followed by "Orova" with 10 and "Market X" with 9. This clustering suggests that a handful of operators are responsible for a disproportionate share of observed activity, potentially indicating coordinated campaigns or the use of shared infrastructure. The United States remains the top victim country with 43 events, followed by Spain (24) and Indonesia (16). The high volume of defacement events (63) suggests that hacktivist or low-sophistication activity remains a persistent noise floor, while the 41 ransomware events and 34 data breaches represent the more significant operational threats.

The UNC6671 analysis from Google Threat Intelligence is a key signal for defenders. The group's ability to operate multiple extortion brands simultaneously, while maintaining consistent TTPs, indicates a mature and adaptable operation. The shift toward financial and legal sectors, combined with the use of personal mobile numbers for vishing, suggests that traditional email security controls are insufficient. Organizations should prioritize phishing-resistant MFA, enforce session controls, and monitor for abandoned MFA challenge patterns in identity provider logs. The exposed Rockwell PLCs also serve as a reminder that operational technology remains a vulnerable attack surface, particularly in critical infrastructure sectors.

All incidents are reported as alleged claims by threat actors and have not been independently verified by GrayscaleInsight.

Threat intelligence is reported for security awareness purposes only and does not constitute endorsement of any actor, group, or activity.

Recent editions