SECURITYTHE HACKER NEWS
UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
Cybersecurity researchers revealed a data theft extortion campaign targeting U.S. organizations in professional, legal, and financial services between January and May 2026. The campaign, attributed to UNC3753, involved vishing and physical intrusions, with Google Mandiant and Google Threat Intelligence Group identifying the threat actor.
Mentioned
Related Signal
Adjacent reporting
- FBI warns of in-person data theft attacks from extortion gang
- Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
- BlackFile actively extorting data-theft victims in retail and hospitality sector
- Two new extortion crews are speedrunning the Scattered Spider playbook
- If you don't fall for these extortionists' calls, they'll show up with USB sticks
- Microsoft Self-Service Password Reset abused in Azure data theft attacks