redact
ransomware group · aka Redact, UNC6671 (Mandiant-designated cluster tied to the Redact extortion site; a cluster tracking identifier, not a confirmed alias) · unknown (no public attribution of nationality or base; Mandiant noted possible overlap with the broader social-engineering ecosystem behind 2025 Salesforce extortion campaigns, without firm attribution) · active since August 2025, when Mandiant's reporting on UNC6671 described the Redact extortion site; exact first-activity date unknown
Redact is a data-theft extortion brand that publishes victim claims on its own leak site; it does not deploy ransomware and relies solely on threatened exposure of stolen data. Google Cloud Mandiant's August 2025 reporting tied the Redact site to UNC6671, a financially motivated cluster that voice-phishes employees on personal (unmanaged) phones, often impersonating IT personnel, to obtain SaaS credentials and exfiltrate Salesforce data using legitimate tools such as Data Loader. Mandiant noted tactical overlap with the social-engineering ecosystem behind 2025 Salesforce extortion campaigns (UNC6040, widely linked to ShinyHunters), but public attribution and country of origin remain unknown. Publication volume is low - two victims (Hologic, FCCI Insurance Group) tracked since the dashboard's monitoring start on 2026-06-27 - consistent with selective extortion, though the true victim count is likely higher because settlements can be private. No public earnings figures or CVEs are associated with the group's intrusions, which rely on social engineering and credential abuse rather than software vulnerabilities.
- Vishing: phone calls to employees' personal, unmanaged devices while impersonating IT/helpdesk staff to harvest credentials and MFA approvals (Mandiant, 2025)
- Credential-based unauthorized access to SaaS platforms, with a focus on Salesforce (Mandiant, 2025)
- Data exfiltration using legitimate native tooling, e.g., Salesforce Data Loader (Mandiant, 2025)
- Pure data-theft extortion: victims threatened with publication on the Redact leak site; no ransomware encryption observed (Mandiant, 2025)
- Tradecraft shared with UNC6040, which used vishing and abuse of legitimate Salesforce connected apps in 2025 Salesforce campaigns (Mandiant, 2025)
Hologic (medical diagnostics/healthcare), FCCI Insurance Group (US commercial insurance carrier)
No public figure.
Leak-site victims2 posts · newest first
| Victim | Discovered | Details |
|---|---|---|
| Hologic | · Jun 27, 2026 | — |
| FCCI Insurance Group | · Jun 27, 2026 | — |