BlackFile Actively Extorting Data-Theft Victims in Retail and Hospitality

Share
A silhouette of a telephone handset with a digital file folder leaking binary data.

A new extortion gang known as BlackFile — assessed with moderate confidence by Unit 42 to be linked to the broader criminal network “The Com” — has been targeting retail and hospitality organizations since February 2026, using vishing-to-fake-SSO-phishing chains to steal credentials, exfiltrate SaaS data, and demand seven-figure ransom payments.

ARLINGTON, VIRGINIA — A surge in sophisticated voice-phishing (vishing) attacks has put the retail and hospitality sectors on high alert as a new threat actor, dubbed BlackFile, scales its operations. Unlike traditional ransomware groups that prioritize file encryption, BlackFile focuses almost exclusively on "data-theft-and-extortion." By combining old-school human engineering with modern SaaS API exploitation, the group has breached organizations across the retail and hospitality sectors, threatening to leak sensitive employee records and customer PII unless seven-figure ransoms are met.

The group’s tactics signal an aggressive evolution in the "extortion-first" model. Security researchers from Palo Alto Unit 42 and the RH-ISAC (Retail & Hospitality ISAC) describe an operation built around a dedicated data-leak site, where the threat of publication — and staged releases of stolen files — is the primary instrument of pressure. That leak-site leverage, combined with the real-world harassment reported around this ecosystem — Unit 42 and the RH-ISAC documented swatting attempts against employees, including senior executives, of compromised companies — marks BlackFile as one of the most volatile threats to emerge in the first half of 2026.

Editor’s note: CrowdStrike now tracks the operators behind the BlackFile data-leak site as Cordial Spider, assessed alongside a related cluster it calls Snarky Spider. Unit 42 tracks the same activity as CL-CRI-1116; Mandiant/Google tracks it as UNC6671. CrowdStrike reported that the BlackFile leak-site domain was offline as of late April 2026. Our follow-up coverage details the attribution and where the two clusters' tactics diverge: Cordial Spider and Snarky Spider: vishing, SSO abuse, and SaaS extortion.


Threat Intelligence: BlackFile Extortion Profile

Threat Intelligence: BlackFile (CL-CRI-1116 / UNC6671)
Metric Detail
Primary Sectors Retail, Hospitality, Healthcare, Logistics
Initial Access Vishing (IT Helpdesk Impersonation)
Attack Chain Fake SSO Phishing → New Device MFA Bypass
Extortion Style Leak-Site Pressure; Seven-Figure Ransoms
Aliases BlackFile · CL-CRI-1116 (Unit 42) · UNC6671 (Mandiant/Google) · Cordial Spider (CrowdStrike)

The Vishing-to-SSO Attack Chain

The BlackFile playbook begins with a high-pressure phone call. Attackers spoof VoIP numbers and caller ID names (CNAM) to pose as internal IT helpdesk staff. They target front-line retail or hospitality employees, claiming there is an "urgent security sync" required for their account.

The victim is directed to a pixel-perfect fake corporate Single Sign-On (SSO) login page. When the victim enters their credentials and provides a one-time MFA passcode to the "IT representative," the attackers use that real-time data to register a new rogue device or hijack the session. Once inside the SaaS environment, the group abuses application APIs — combing Salesforce records and SharePoint document libraries — to identify files containing keywords like "confidential," "SSN," or "Salary."

Psychological Warfare and "The Com" Connection

Unit 42 researchers have linked BlackFile, with moderate confidence, to a broader, loosely-affiliated criminal network known as “The Com.” This ecosystem is notorious for blending digital crimes with real-world harassment. Unit 42 and the RH-ISAC report that employees of compromised companies — including senior executives — have been targets of swatting attempts, in which attackers call in false police dispatches to a victim's home. Attribution of the tactic is not uniform across vendors: CrowdStrike, which tracks the operators behind the BlackFile leak site as Cordial Spider, attributes swatting specifically to a separate cluster it calls Snarky Spider, describing it as that group's escalation of choice, and points to DDoS attacks as the more general consequence for victims who refuse to pay.

Communications often arrive via random Gmail addresses or even the compromised inboxes of the company's own employees. Victims are then pressured with the prospect of publication on a dedicated dark web leak site — a posture designed to push organizations into "damage control" from the moment of discovery.


What to Do Now: Immediate Actions

  • Implement "Callback" Protocols: Train staff to never provide credentials or MFA codes over the phone. Enforce a policy where employees must hang up and call the IT department back using a verified internal extension.
  • Audit New Device Registrations: Monitor SSO logs for any new device enrollments or MFA method changes that occur immediately following a successful login, especially from unusual IP ranges.
  • Harden SaaS API Access: Review and rotate API keys for Microsoft 365 and Salesforce environments. Restrict the ability of standard user accounts to perform bulk data exports via API.
  • Executive Security Briefing: Unit 42 and the RH-ISAC documented swatting attempts against employees and senior executives of BlackFile victims, while CrowdStrike attributes swatting specifically to Snarky Spider as that cluster's escalation tactic and cites DDoS as the general consequence for non-payment. Either way, brief senior leadership on the direct-harassment risk and make sure corporate security and local law enforcement are prepared.

The CyberSignal Analysis: Strategic Signals

Signal 01 — The Industrialization of Vishing

BlackFile’s success highlights that technical MFA controls can be rendered useless by a convincing voice. While many organizations have spent millions on "unphishable" hardware keys, BlackFile bypasses this by targeting the humans who manage the keys. In sectors like retail and hospitality, where staff turnover is high, this human attack surface remains the path of least resistance.

Signal 02 — SaaS Data as the New Ransomware

As companies move more "crown jewel" data into SharePoint, OneDrive, and Salesforce, threat actors are following. BlackFile represents the trend of extortion-only groups who realize that stealing a terabyte of PII is often more profitable than maintaining encryption infrastructure. We saw a similar prioritization of data theft over operational disruption in the ADT data breach, where attackers leveraged initial access to exfiltrate millions of records from a trusted security provider.

Signal 03 — The Convergence of Digital and Physical Threat

The swatting attempts Unit 42 and the RH-ISAC documented against BlackFile victims — and CrowdStrike's separate attribution of the tactic to Snarky Spider — mark a dangerous bridge between cybercrime and physical violence. Previously confined to niche online harassment circles, swatting is now surfacing in high-stakes corporate extortion, requiring a coordinated response between CISOs and physical security teams.


Sources

Type Source
Technical CyberScoop: BlackFile Extortion Analysis
Industry RH-ISAC: Extortion in the Enterprise
Reporting BleepingComputer: BlackFile Incident Coverage