216.73.216.197

Latest goon squad to use fake helpdesk calls to steal creds

· Published 04/06/2026 22:52 · Modified 05/06/2026 06:41

Export JSON

Essential information

Published
04/06/2026 22:52
Modified
05/06/2026 06:41
Tags
2026-06-04 cloud data theft credential phishing extortion helpdesk impersonation mfa bypass social engineering the com vishing
Related entities
2 observables, 1 intrusion sets (apt), 3 others

Description

A new group called Pink, tracked as cluster CL-CRI-1147, employs voice phishing and fake IT to compromise organizations. The gang steals employee credentials, bypasses multi-factor authentication, and exfiltrates data from cloud storage platforms like SharePoint and OneDrive. Pink threatens to leak stolen information unless ransom demands are met, setting 72-hour deadlines. The group's data-leak site launched on May 31, 2026. This approach mirrors tactics popularized by Lapsus$, Scattered Spider, and ShinyHunters. Incident responders link Pink to , a loosely connected network of English-speaking hackers and extortionists. Attackers use compromised victim accounts and internal Teams messages for communications, reusing domains across multiple targets.

External references