New Extortion Brand Uses IT Impersonation to Breach Organizations

KnowBe4 Team | Jun 23, 2026

A newly surfaced extortion brand called “Pink” is using voice phishing and fake IT support calls to breach organizations, the Register reports. The threat actor may be a rebrand of prior extortion groups, including BlackFile and Redact, though its tactics remain the same.

Palo Alto Networks’s Unit 42 said in a post on Github, “The threat actor leverages vishing for initial access, impersonating internal IT personnel to convince a user to input credentials into a phishing site, allowing the actor to gain access to the victim's account and MFA. After gaining access to the victim's account, the actor rapidly identifies and exfiltrates data from platforms like SharePoint and OneDrive, similar to other Com-affiliated groups. Shortly afterward, the actor leverages a compromised victim account to send their initial extortion email as well as internal Teams messages. The actor reuses second-level domains to target multiple organizations, and the third-level domain typically thematically represents the target. These domains have leveraged DDoS-Guard for hosting.”

The Register notes that criminal gangs frequently go dark before resurfacing under different names, but these groups continue to grow more sophisticated over time.

“Despite multiple arrests across all three gangs, they keep coming back to victimize more organizations,” the Register says. “Most incident responders, including Google’s Mandiant and Unit 42, link many of these criminal collectives to The Com, a loosely knit group of primarily English speakers made up of several interconnected networks of hackers, SIM swappers, and extortionists, with some of its subgroups offering real-life violent crime for hire.”

The Register has the story: Pink is the latest goon squad to use fake helpdesk calls to steal creds

Secure Your Human and AI Workforce

Transform your attack surface into your strongest defense with our AI-driven platform. Request a personalized demo to see how to mitigate social engineering, manage agent risk, and automate your phishing response.

Get a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.