August 20, 2026

Active Voice Phishing Campaigns Targeting FIs

Introduction

Vishing is an increasing social-engineering threat to financial institutions, with attackers impersonating trusted IT or business contacts to obtain employee credentials, multi-factor authentication (MFA) OTP codes, or session access, potentially leading to data theft, system compromise, and extortion. Recent cyber threat reporting from multiple industry sources indicates that threat actors are increasingly using spoofed helpdesk calls, fake login portals, and MFA re-enrolment pretexts to bypass conventional controls and compromise enterprise cloud environments. While many reported cases involve U.S. firms, these tactics are equally relevant to Singapore-based financial institutions given their reliance on remote support, cloud services, and employee authentication workflows.

Difference between Vishing, Phishing, and Smishing

Vishing, phishing, and smishing are all social-engineering techniques designed to trick individuals into disclosing sensitive information, approving fraudulent activity, or enabling unauthorised system access. The key difference is the communication channel used by the attacker.

Threat Type Primary Channel Typical Objective Example
Vishing Voice call or voicemail Obtain credentials, MFA OTP codes, payment approvals, or account information through verbal deception. A caller impersonates IT support and asks an employee to re-enrol MFA or disclose an OTP.
Phishing Email or web link Direct users to malicious links, fake login pages, or infected attachments. An email claims the user must verify their account through a spoofed login page.
Smishing SMS or messaging app Prompt users to click malicious links or disclose account details through mobile messages. A text message claims an account will be frozen unless the user confirms their credentials.

Vishing Examples

  • Help Desk Password Reset: Attackers pose as IT support staff, claiming that a system migration requires an urgent password change or MFA re-enrolment, allowing the attacker to hijack corporate credentials.
  • Executive Voice Cloning / Deepfakes: Cybercriminals use AI-generated voice cloning of a CFO, Managing Director, or other senior leader to instruct a finance employee to make an urgent and confidential wire transfer.
  • Vendor Bank-Change Pretexting: Scammers call the accounts payable department pretending to be an established supplier and request an immediate change to vendor bank account details.

Recent Vishing Incident

On 7 August 20261, Google’s Threat Intelligence Group reported vishing campaigns employed by a financially motivated threat cluster tracked as UNC6671. While UNC6671 has not been directly attributed to the recent attacks on U.S firms, the group has historically used vishing to support ransomware and data-extortion activity against the financial and legal sectors in Australia, Canada, and the United States.

UNC6671’s vishing activity involves targeting employees’ personal mobile devices directly and, in some cases, spoofing legitimate IT helpdesk numbers to appear credible2. Victims are directed to spoofed login portals hosted within adversary-in-the-middle (AiTM) infrastructure, which intercepts credentials and MFA session tokens in real time. These portals are typically designed to mimic enterprise authentication pages, using pretexts such as passkey enrolment, MFA re-enrolment, or Single Sign-On migration. Once attackers gain access through an employee account, automated scripts are used to exfiltrate data from enterprise cloud environments such as Microsoft 365 and Okta. To delay detection, attackers may delete password-reset indicators or related alerts.

In addition to conventional extortion tactics such as encrypted communication channels and short response deadlines, UNC6671 is known to hijack internal corporate platforms to message executives and HR personnel directly, increasing pressure during ransom negotiations involving exfiltrated data.

Warning Signs

  • An unsolicited telephone call concerning your account, a purported “security issue,” or a request to “verify your identity.”
  • A request to disclose your password, personal identification number, or a one-time passcode sent to your registered device.
  • A request to access an unfamiliar website to “re-enrol,” “confirm,” or “migrate” your account credentials.
  • Pressure to act immediately, including threats that your account will be suspended, frozen, or disabled.
  • Spoofed phone numbers that appear to be from trusted businesses or institutions, subtly different from the real ones.

Recommended Actions

The activity attributed to UNC6671 highlights how threat actors can combine voice-based social engineering with adversary-in-the-middle (AiTM) infrastructure to bypass authentication controls and access enterprise environments. To reduce exposure to similar threats, financial institutions should consider the following actions:

  • Review controls on employee login sessions and monitor for session-token reuse, unusual authentication patterns, and suspicious TLS fingerprinting.
  • Raise employee awareness on voice-phishing tactics, including spoofed helpdesk calls, requests for MFA codes, and prompts to enrol in passkey or SSO migration processes.
  • Apply safeguards such as holding periods, dual control for MFA reset and re-enrolment requests, and independent notifications to both user and security team.
  • Establish out-of-band verification procedures for unsolicited helpdesk or IT support calls, enabling employees to validate callers through a known and trusted channel.
  • Monitor for lookalike domains and phishing websites impersonating the organisation to support timely takedown.
  • Share relevant cyber-threat information with MAS’ Research & Intelligence team.

How We Can Help

At Kai Global, we partner with various IT specialist firms, to assist you in understanding of your IT security, performing GAP analysis, and proposing action plans to achieve your IT resilience and data protection objectives.

Client should remain alert to unsolicited request for sensitive authentication information. Kai Global will never request passwords, PINS, MFA OTP codes, or one-time passcodes over the phone. If you are unsure whether a call, message, or email from us is genuine, please contact us immediately through our official website or approved contact channels.


References:

  1. UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments | Google Cloud Blog
  2. Welcome to BlackFile: Inside a Vishing Extortion Operation | Google Cloud Blog

Contact us

Join the ranks of successful clients who trust KAI Global Consulting for expert advice by arranging your personalized strategy session today.

    By submitting, I agree to Kai Global's Privacy Policy

    Thank you for your inquiry. Our team of professionals with get back to you shortly

    In the meantime, feel free to browse our contents