BlackFile, Helix, and the Rebrand Treadmill: How a Vishing Crew Is Turning Employee Home Data Into a Weapon
Published by Priwall by mePrism
BlackFile, Helix, and the Rebrand Treadmill: How a Vishing Crew Is Turning Employee Home Data Into a Weapon
A financially motivated data-extortion crew that operated in 2026 under the "BlackFile" brand — tracked in parallel by Palo Alto Networks Unit 42 as CL-CRI-1116, by Google/Mandiant as UNC6671, and by CrowdStrike as Cordial Spider — shut down its leak site in April 2026 and immediately began re-emerging under new names, including Redact, Pink, and, most recently, Helix. The playbook has not changed: voice phishing (vishing) against employees, single sign-on (SSO) session theft, mass exfiltration of SharePoint and Salesforce, and seven-figure "pay or leak" demands (Palo Alto Networks Unit 42 / RH-ISAC; ReliaQuest; BleepingComputer; TechNadu).
What is changing is how the group applies pressure. Unit 42 and Google Threat Intelligence Group (GTIG) have confirmed that BlackFile-lineage actors swat C-suite executives at their homes to force ransom payments (Palo Alto Networks Unit 42 / RH-ISAC; CyberScoop). Independent cybersecurity researchers tracking the parent ecosystem — "The Com" — have documented an ongoing shift toward real-world violence, including bricking, arson, home invasion, and paid "violence-as-a-service" contracts (FBI PSA / The Record; CyberScoop on FBI IRL Com; KrebsOnSecurity).
A cybersecurity executive briefed us off the record that this group has now dispatched a vandal to the home of a victim as part of an extortion sequence, and is currently focused on oil and gas operators and private equity firms, with 5–10 new victims per week. We could not independently corroborate the specific incident or the sector-weekly cadence in public reporting, and we note that clearly below. What we can corroborate is that this exact escalation pattern — cyber intrusion followed by physical intimidation at home — is now a documented feature of the Com ecosystem BlackFile emerged from (FBI PSA / The Record; KrebsOnSecurity on Scattered Lapsus ShinyHunters; Barracuda Networks).
The reason this matters to a data-removal company is simple. Every one of these physical escalations — swatting, bricking, "showing up at the house" — requires the same input: a current home address for the target. That address almost always comes from open-source people-search sites and data brokers. Removing that address from those sources is not a nice-to-have privacy gesture. In 2026, for a CEO, CFO, or GC at an oil-and-gas or PE-backed target, it is a physical-security control.
Who BlackFile is, in plain language
BlackFile is not a nation-state, and it is not a traditional ransomware crew that encrypts systems. It is a financially motivated, largely English-speaking data-theft-and-extortion cluster that Unit 42 assesses with moderate confidence is affiliated with The Com — the loosely organized online cybercrime collective known for aggressive social engineering, swatting, and recruitment of minors (Palo Alto Networks Unit 42 / RH-ISAC; CyberScoop; The Hacker News).
Different vendors track the same activity under different names:
| Vendor / Researcher | Designation |
|---|---|
| Palo Alto Networks Unit 42 | CL-CRI-1116 |
| Google Threat Intelligence Group / Mandiant | UNC6671 |
| CrowdStrike | Cordial Spider |
| Public leak-site brand | BlackFile |
The overlapping designations reflect competing vendor telemetry with shared tradecraft fingerprints, not distinct groups (Google Mandiant on X; Mallory profile of UNC6671).
Public activity began in January 2026, escalated in February, and by April 2026 the group had shut down the BlackFile leak site — likely under law enforcement pressure and to shed reputation exposure (ReliaQuest; BleepingComputer). GTIG's Austin Larsen has stated that after retiring the BlackFile brand in May 2026, the group launched Redact, then Pink (tracked by Unit 42 as CL-CRI-1147), then likely Helix (TechNadu / GTIG; Arete IR).
Note: the Helix name here is unrelated to the older Helix Kitten / APT34 / OilRig Iranian espionage cluster and unrelated to the ransomware attack on Helix Energy Solutions (helixesg.com) by the Clop ransomware group in November 2025 (CrowdStrike on Helix Kitten; Breachsense on Helix ESG). The Wall Street Journal has explicitly documented that veteran extortion crews now rebrand aggressively to evade detection by defenders and law enforcement (Wall Street Journal Pro Cybersecurity).
The playbook: no malware, pure identity abuse
The reason BlackFile/Helix has scaled so quickly is that the attack chain contains almost no traditional malware. It runs on identity theft and process abuse, which means most existing endpoint and network defenses never trigger.
Per Unit 42's joint report with the Retail & Hospitality ISAC, the standard kill chain is (Palo Alto Networks Unit 42 / RH-ISAC):
Reconnaissance on employees. The attacker identifies a target employee — often help-desk staff, a manager the attacker can spoof, or a junior admin — using open-source directories, LinkedIn, and internal contact lists exposed in prior breaches.
Vishing call. The attacker calls the employee from a spoofed VoIP number or fraudulent caller-ID name (CNAM), posing as IT support. In some Helix cases, ReliaQuest observed the attacker spoofing the target's direct manager by name on caller ID (ReliaQuest).
Adversary-in-the-middle (AiTM) SSO page. The employee is directed to a phishing site that mirrors the corporate SSO portal. Attackers use antidetect browsers and residential proxies geo-matched to the target to bypass IP-reputation filters (Palo Alto Networks Unit 42 / RH-ISAC; OffSeq).
Credential and TOTP capture. Username, password, and the live time-based one-time password (TOTP) are relayed in real time.
MFA persistence. The attacker registers a device or MFA app of their own on the account (MITRE ATT&CK T1098.005), which persists after the stolen TOTP expires (Palo Alto Networks Unit 42 / RH-ISAC).
Directory scraping and privilege escalation. The attacker scrapes internal employee directories for executive contact info and pivots into senior accounts through additional social engineering.
Mass exfiltration via legitimate APIs. Using Microsoft Graph Sites.Read.All, Salesforce APIs, and standard SharePoint downloads, the group exfiltrates whole SaaS estates. Files matching keywords like "confidential" and "SSN" are prioritized. Data is often staged through LimeWire or MEGA (Palo Alto Networks Unit 42 / RH-ISAC).
Extortion. A seven-figure ransom demand is sent from a random alphanumeric Gmail address or, notably, from a compromised employee's own email account (SC Media; Palo Alto Networks Unit 42 / RH-ISAC).
Pressure phase. If the victim refuses to pay, the group escalates: leak-site listing, email flooding of executives, DDoS of the corporate site, and — the piece that matters here — swatting of executives at their homes (Palo Alto Networks Unit 42 / RH-ISAC; SC Media; KrebsOnSecurity).
Dwell time from initial credential theft to mass exfiltration ranges from under an hour to over a week in the Helix cases ReliaQuest documented (ReliaQuest).
The physical-intimidation escalation
This is where the story stops being about SaaS security and starts being about executive protection.
Confirmed on the record: swatting of C-suite personnel
Unit 42's April 2026 joint report with RH-ISAC explicitly states that CL-CRI-1116 (BlackFile) "may attempt to SWAT C-suite executives or other company personnel to further coerce ransom payment" (Palo Alto Networks Unit 42 / RH-ISAC). SC Media independently reported the same swatting behavior in the BlackFile campaign (SC Media). CyberScoop's April 27 coverage of Unit 42's assessment carries the same finding (CyberScoop).
Swatting is not a prank. It is the transmission of a false emergency — typically a hostage situation or active shooter — to police at the target's residence, with the goal of triggering an armed tactical response. The FBI catalogs it as a serious violent crime and has warned that Com-affiliated subgroups advertise swat-for-hire contracts on messaging apps (CyberScoop on FBI IRL Com).
Documented in the broader ecosystem: real-world violence
The FBI's July 2025 Public Service Announcement on The Com — the ecosystem BlackFile emerged from — was blunt. The bureau confirmed that Com members have used kidnapping, torture, threats of violence against family members, firearms, shootings, armed robbery, stabbings, physical assault, and "bricking," and that a specific subgroup — "IRL Com" — openly offers "violence-as-a-service" (FBI PSA / The Record; CyberScoop on FBI IRL Com).
Microsoft's own threat intelligence team documented Scattered Spider — another Com offshoot with confirmed tradecraft and personnel overlap with the BlackFile/ShinyHunters ecosystem — sending messages like "If we don't get ur login in the next 20 minutes we're sending a shooter to your house" and "ur wife is gonna get shot if you don't fold it" to employees at victim organizations (CyberScoop on Microsoft research; Motley Fool discussion citing Microsoft).
KrebsOnSecurity, reporting on the closely related Scattered Lapsus ShinyHunters (SLSH) group in February 2026, wrote that the crew's extortion playbook includes "harassing, threatening and even swatting executives and their families," with multiple executives at targeted organizations having received phony bomb threats or hostage-situation calls staged at their home addresses (KrebsOnSecurity). Barracuda's July 2026 threat trend piece confirmed the same pattern industry-wide: "threat actors are also gathering personal data about staff, including home addresses and family details, to increase pressure" (Barracuda Networks).
CrowdStrike's H1 2026 European Threat Landscape Report identified at least 18 European cybercrime incidents involving real-world violence since the start of 2025, describing an escalating "violence-as-a-service" trend inside the Com ecosystem (CrowdStrike via Mallory).
The off-the-record report to Priwall
A senior cybersecurity executive briefed Priwall — on background, not for direct attribution — that the BlackFile/Helix-lineage crew has now progressed beyond swatting to sending a vandal to the residence of a victim as part of an ongoing extortion sequence, and that the current targeting is concentrated on oil-and-gas operators and private-equity firms at a pace of 5–10 new victims per week.
We could not independently verify that specific incident or the exact weekly cadence in public reporting as of publication. What we can say is that:
The escalation profile — cyber intrusion followed by targeted physical intimidation at the home address — is already the documented signature of the Com ecosystem, per the FBI, KrebsOnSecurity, Microsoft, and CrowdStrike (FBI PSA / The Record; KrebsOnSecurity; CyberScoop on Microsoft research; CrowdStrike via Mallory).
The FBI has publicly documented "bricking" — hurling objects through the windows of a victim's residence — as one of the Com's in-real-life tactics (FBI PSA / The Record).
A separate but adjacent extortion crew, Silent Ransom Group / UNC3753 / Luna Moth, has already been observed physically walking into victim offices with USB drives, per Google Mandiant and an FBI alert — proof that in 2026, "we'll come there ourselves" is no longer a bluff in this ecosystem (The Register; CNN).
We treat the off-the-record report as consistent with the documented threat trajectory and are publishing it as such. Enterprises should not wait for a court-documented BlackFile home-vandalism case before hardening executive residential exposure.
The sector question: oil and gas and private equity
Public Unit 42 and Mandiant reporting on BlackFile has emphasized retail, hospitality, healthcare, technology, transportation, logistics, and wholesale as the sectors seen most in incident-response caseloads through Q2 2026 (Palo Alto Networks Unit 42 / RH-ISAC; CyberScoop; Mallory profile of BlackFile).
The oil and gas and private equity focus reported to us off the record is not yet the public center of gravity for BlackFile, but it is directionally consistent with three well-documented facts:
The Com ecosystem has repeatedly hit energy and financial services. ShinyHunters — with which BlackFile shares tradecraft, infrastructure, and personnel — has already extorted a long list of financial-services and PE-adjacent targets in 2026, including Mercer Advisors, Beacon Pointe Advisors, Ameriprise Financial, CFGI Management, Aura Group, Marcus & Millichap, Pathstone Family Office, Berkadia, Ryan LLC, Kemper Corporation, Abrigo, and Canada Life Assurance (Privacy Insight Solutions summary; Push Security).
BlackFile is opportunistic. Unit 42 describes the group as attacking whoever has weak help-desk controls and a rich SharePoint estate, regardless of vertical (Palo Alto Networks Unit 42 / RH-ISAC; CyberScoop). Both criteria describe most upstream energy operators and mid-market PE portfolio companies.
The energy sector is under sustained multi-actor pressure. Clop ransomware listed offshore-energy provider Helix ESG on its leak site in November 2025 (Breachsense; DeXpose). Iranian-linked APT34 / OilRig continues to run espionage against oil and gas operators globally (Trustwave via LevelBlue; Brandefense). A BlackFile-lineage crew pivoting into this environment is a low-friction move.
The "5–10 new victims per week" cadence reported to us is also plausible in the aggregate. ShinyHunters alone claimed 1.5 billion Salesforce records across 1,000+ organizations and named 40+ victims in the first half of 2026 (Push Security). BlackFile's data-leak site was actively listing victims throughout Q1 and Q2 2026 before it went dark (CyberScoop).
We flag this as directional, not yet publicly verified for BlackFile specifically. If you are a CISO or GC at an oil-and-gas or PE-backed firm and you are hearing similar things through ISAC channels or your outside counsel, that is worth reporting to the FBI's IC3 immediately.
Why the home address matters — and why brokers are the choke point
Every physical escalation in this playbook — swatting, bricking, showing up at a residence with a USB drive, showing up with a rock — has a single prerequisite: the attacker needs the target's current home address.
Attackers do not generally get that address from the breach itself. They get it from people-search sites and data brokers. Sites like Radaris, Spokeo, WhitePages, BeenVerified, and dozens of others aggregate public-records, marketing, and telecom-derived data into a free-to-search profile that reliably surfaces an executive's home address, phone number, family members' names, and neighbors — for anyone with a browser.
This is the choke point that Priwall by mePrism attacks. Priwall submits authorized-agent removal requests, CCPA/CPRA opt-out demands, and state-level right-to-delete filings against the broker layer at enterprise scale. In Priwall's enterprise cohort, that has translated to a published removal rate of over 90% against the data-broker set our workforce customers care about.
For an oil-and-gas or PE-backed target being pressured by a BlackFile-lineage crew, removing an executive's residential address, phone number, and family-member links from the open broker layer accomplishes three things at once:
It breaks the swatting chain. Attackers who cannot confirm the target's current address before making the false police call take on real risk of a wrong-house response — a signal loss that measurably reduces the tactic's utility. Unit 42 explicitly identifies swatting as a coercion mechanism BlackFile uses (Palo Alto Networks Unit 42 / RH-ISAC).
It denies the bricking / home-visit playbook. The FBI has confirmed that Com members use bricking as an intimidation tactic (FBI PSA / The Record). No address, no drive-by.
It hardens the vishing pretext. In several Helix cases, attackers spoofed the direct manager's caller ID and referenced personal context to make the "IT support" call feel legitimate (ReliaQuest). That personal context — where an executive lives, who lives with them, what their neighborhood context is — comes from the broker layer.
Broker data is no longer a marketing problem. It is fuel for identity-based cyber attacks and for the physical follow-through those attacks now include. Barracuda, KrebsOnSecurity, and CrowdStrike are all now saying the same thing: incident-response plans in 2026 must integrate a physical-threat lane, and that lane starts with what open sources say about your executives (Barracuda Networks; KrebsOnSecurity; CrowdStrike via Mallory).
What defenders should do right now
The threat is dual-track — SaaS-identity on one side, physical-address exposure on the other — and both tracks need attention this quarter.
SaaS-identity controls (based on Unit 42, Mandiant, and ReliaQuest guidance)
Move help-desk password resets and MFA re-enrollments off single-call workflows. Require a second, out-of-band verification channel. Unit 42's core recommendation is to limit what IT support can complete in a single call (Palo Alto Networks Unit 42 / RH-ISAC).
Deploy phishing-resistant MFA (FIDO2 / passkeys) for anyone with admin rights in Okta, Entra ID, Google Workspace, Salesforce, or SharePoint. Push-based MFA is defeated by AiTM and device-code phishing in this playbook (ReliaQuest; BleepingComputer).
Alert on unusual MFA device registration events. BlackFile persistence hinges on the attacker adding a device or authenticator app under their control (MITRE T1098.005) (Palo Alto Networks Unit 42 / RH-ISAC).
Baseline and monitor Microsoft Graph API usage — especially Sites.Read.All — and Salesforce API bulk-export activity. BlackFile's exfiltration is invisible to endpoint tooling because it runs through legitimate APIs under a legitimate SSO session (Palo Alto Networks Unit 42 / RH-ISAC).
Rehearse frontline phone staff on vague-answer / urgent-request social engineering. Unit 42 specifically calls out simulation-based training as the highest-yield defense against the vishing IT-impersonation vector (Palo Alto Networks Unit 42 / RH-ISAC).
Executive and workforce exposure controls
Run a residential exposure audit on your top-30 executives and their family members. Assume the attacker will do this before you do.
Remove executive residential data from the data-broker layer at scale. This is what Priwall by mePrism does for enterprise customers — with a documented removal rate of over 90% against the broker set that matters for workforce protection.
Extend the same removal to high-privilege engineers, help-desk leads, and finance approvers. BlackFile targets whoever can be socially engineered into giving up SSO. That is a much wider blast radius than the C-suite.
Bring physical security and cybersecurity into the same incident-response plan. As Barracuda puts it, the line between the two is now gone (Barracuda Networks).
If you are contacted
Do not negotiate directly. Groups in this ecosystem have been observed increasing physical pressure the longer negotiations run (KrebsOnSecurity).
Report to the FBI at IC3.gov and your sector ISAC. RH-ISAC, E-ISAC, and FS-ISAC are already tracking this activity (Palo Alto Networks Unit 42 / RH-ISAC).
Notify local law enforcement in the residential jurisdictions of every named executive. This creates an early flag against a swatting call and shortens response time to a bricking or home-visit incident.
The rebrand treadmill will not stop
BlackFile is not the beginning of this problem and Helix is not the end of it. The Wall Street Journal reported in July 2026 that veteran extortion attackers are cycling brand names specifically to evade defender attribution (Wall Street Journal Pro Cybersecurity). ReliaQuest summarized the pattern clearly: "Groups fragment and rebrand, but the techniques and infrastructure persist across every iteration" (ReliaQuest).
The name on the leak site is the least durable piece of this threat. The vishing playbook, the SSO-session theft, the SharePoint exfiltration, the seven-figure demand, the swat call to the CEO's house — those are durable. The choke point that lets the physical-intimidation half of the playbook work — an executive's home address sitting on Radaris — is durable too.
That last one is the one enterprises can actually take away. That is the piece Priwall by mePrism removes.
If your organization is in oil and gas, in private equity, or in any sector where a leak site is beginning to feel like an active operational risk, the Priwall team can run an exposure audit on your executive population and give you a same-week removal plan. Contact us at priwall.io or learn more about the mePrism parent brand at meprism.com.
Ready to try Priwall by mePrism yourself?
If you are an individual executive evaluating personal coverage outside an employer-funded program, you can start with a free exposure scan.
Sign up for Priwall by mePrism coverage.Tom Daly is the founder and CEO of Priwall by mePrism, the enterprise open-source data-removal platform used by security, executive-protection, and digital-risk teams to shrink broker exposure across 700+ U.S. data brokers. He writes on data privacy, cybersecurity, and constitutional privacy at the Priwall blog and on LinkedIn.