ZeroHour

falcon

ransomware group · aka Falcon (leak-site brand), UNC6671 (Mandiant-tracked cluster associated with the group's intrusion activity, per public reporting), BlackFile (mentioned in connection with the group in recent reporting; relationship not firmly established) · unknown · active since unknown; this dashboard began tracking the group's leak site on 2026-08-29

Victims · 7d
0flat
Victims · 30d
3active targets
Victims · 90d
3
All-time (tracked)
3since 2026-08-29
Last post
08-31 17:24UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Falcon is a financially motivated data-theft extortion group whose leak site this dashboard has tracked since 2026-08-29, listing three victims to date (Hayward Holdings, Globus Medical, and DistributionNOW), with the most recent post on 2026-08-31. Public vendor research associates the group's intrusions with the Mandiant-tracked cluster UNC6671, which conducts voice-phishing (vishing) attacks against employees' personal phones to steal SaaS credentials and data for extortion. Recent reporting has also discussed the group in connection with BlackFile, an operation reported to be attacking financial companies, though the precise relationship between the two names remains unclear. The group's origin and earnings are unknown, and no CVE exploitation has been widely reported, with its attacks described as social-engineering-driven.

Tactics & tooling
  • Voice phishing (vishing) targeting employees on their personal mobile phones, reportedly impersonating IT or support staff
  • Social-engineering harvesting of SaaS credentials and MFA approvals
  • Unauthorized access to, and exfiltration of, data from SaaS applications
  • Data-theft extortion with victims named on a public leak site; ransomware deployment not widely reported
  • Targeting of personal devices and out-of-band channels to bypass corporate security controls
Targeted sectors
Manufacturing (e.g., pool equipment)Medical devices / healthcareIndustrial and energy distributionFinancial services (per reporting on related BlackFile attacks)
Notable public victims

Hayward Holdings (U.S. pool-equipment manufacturer; listed on the group's leak site per this dashboard), Globus Medical (U.S. musculoskeletal medical-device company; listed on the group's leak site per this dashboard), DistributionNOW / DNOW Inc. (U.S. distributor of energy and industrial products; listed on the group's leak site per this dashboard)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Hayward Holdings · 15d ago561 GB compressed · 848 GB uncompressed
Globus Medical · 17d agoMedical devices · NYSE: GMED — 2.38 TB compressed, 2.96 TB uncompressed
DistributionNOW (DNOW Inc.) · 17d agoEnergy & industrial distribution · NYSE: DNOW — 182 GB compressed, 344 GB uncompressed

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .