ZeroHour

redact

ransomware group · aka Redact, UNC6671 (Mandiant-designated cluster tied to the Redact extortion site; a cluster tracking identifier, not a confirmed alias) · unknown (no public attribution of nationality or base; Mandiant noted possible overlap with the broader social-engineering ecosystem behind 2025 Salesforce extortion campaigns, without firm attribution) · active since August 2025, when Mandiant's reporting on UNC6671 described the Redact extortion site; exact first-activity date unknown

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
2
All-time (tracked)
2since 2026-06-27
Last post
06-27 20:22UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Redact is a data-theft extortion brand that publishes victim claims on its own leak site; it does not deploy ransomware and relies solely on threatened exposure of stolen data. Google Cloud Mandiant's August 2025 reporting tied the Redact site to UNC6671, a financially motivated cluster that voice-phishes employees on personal (unmanaged) phones, often impersonating IT personnel, to obtain SaaS credentials and exfiltrate Salesforce data using legitimate tools such as Data Loader. Mandiant noted tactical overlap with the social-engineering ecosystem behind 2025 Salesforce extortion campaigns (UNC6040, widely linked to ShinyHunters), but public attribution and country of origin remain unknown. Publication volume is low - two victims (Hologic, FCCI Insurance Group) tracked since the dashboard's monitoring start on 2026-06-27 - consistent with selective extortion, though the true victim count is likely higher because settlements can be private. No public earnings figures or CVEs are associated with the group's intrusions, which rely on social engineering and credential abuse rather than software vulnerabilities.

Tactics & tooling
  • Vishing: phone calls to employees' personal, unmanaged devices while impersonating IT/helpdesk staff to harvest credentials and MFA approvals (Mandiant, 2025)
  • Credential-based unauthorized access to SaaS platforms, with a focus on Salesforce (Mandiant, 2025)
  • Data exfiltration using legitimate native tooling, e.g., Salesforce Data Loader (Mandiant, 2025)
  • Pure data-theft extortion: victims threatened with publication on the Redact leak site; no ransomware encryption observed (Mandiant, 2025)
  • Tradecraft shared with UNC6040, which used vishing and abuse of legitimate Salesforce connected apps in 2025 Salesforce campaigns (Mandiant, 2025)
Targeted sectors
HealthcareInsurance/financial servicesSector-agnostic targeting of enterprises holding sensitive customer data in SaaS/CRM platforms (Mandiant, 2025)
Notable public victims

Hologic (medical diagnostics/healthcare), FCCI Insurance Group (US commercial insurance carrier)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Hologic · Jun 27, 2026
FCCI Insurance Group · Jun 27, 2026

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .