BlackFile has demanded seven-figure ransoms from retail and hospitality companies since February 2026. Its attack chain contains no malware, no exploit, and no email. Every stage is impersonation.
When Palo Alto Networks’ Unit 42 and the Retail & Hospitality ISAC published a joint advisory on April 24, 2026, the threat group it described was unusual not for what it did but for what it didn’t use. BlackFile, also tracked as CL-CRI-1116 by Unit 42, UNC6671 by Mandiant, and Cordial Spider by CrowdStrike, has been conducting data theft and extortion against retail and hospitality organizations since at least February 2026. The group demands ransoms in the seven-figure range. It has exfiltrated customer records, employee PII, and confidential business documents from Salesforce and SharePoint environments across multiple victims. And it has done all of this without deploying a single line of custom malware.
The advisory’s own language is direct: “The attackers behind CL-CRI-1116 do not rely on custom malware or tooling. Rather, they focus on living off the land through misuse of application programming interfaces and other legitimate internal resources.” What they rely on instead is impersonation, applied at every stage of the operation, from initial access through data theft to the ransom demand itself. CrowdStrike subsequently published its own analysis identifying a companion group it tracks as Snarky Spider, using nearly identical techniques and linked with moderate confidence to The Com, a loose-knit network of English-speaking young cybercriminals with a documented history of extortion, harassment, and the recruitment of minors for criminal activity.
How a phone call becomes a seven-figure ransom
The attack begins where most email security tools have no visibility: on the phone.
BlackFile operators call employees from spoofed VoIP numbers or fraudulent Caller ID names, impersonating the organization’s own IT helpdesk. The caller sounds credible because the script is calibrated to the target environment, referencing the company’s SSO platform, its VPN configuration, or a recent system update that the employee would recognize as plausible. The employee is directed to a URL that appears to be the organization’s legitimate single sign-on page. It is a phishing page built to capture credentials and the time-based one-time password the employee enters in real time.
What happens next is where the operation diverges from conventional credential theft. Rather than using the stolen credentials for a single session, BlackFile operators immediately register their own device in the target’s Microsoft Entra ID environment, making their hardware a trusted part of the authentication chain. They then remove the victim’s existing MFA devices and create inbox rules that automatically delete the notification emails that would otherwise alert the organization to the unauthorized device registration. In a matter of minutes, the attacker has persistent, MFA-bypassed access that mirrors legitimate employee activity in every security log.
From there, the operation escalates through the same impersonation mechanism that opened the door. The Hacker News reported that BlackFile operators scrape internal employee directories to identify executive-level accounts, then use further social engineering to compromise those accounts and gain broad-spectrum access to the organization’s most sensitive SaaS environments. They search Salesforce and SharePoint for files tagged “confidential” and “SSN,” exfiltrate the data through standard API functions that look identical to normal business activity, and present the victim with a ransom demand. CyberScoop reported that victims who declined to pay have been subjected to DDoS attacks against their infrastructure and, in multiple documented cases, SWATting of corporate executives, the practice of reporting fabricated emergencies to trigger armed law enforcement responses at their home addresses.
Why retail and hospitality are the target
BlackFile’s focus on retail and hospitality is not incidental. The sectors share characteristics that make the vishing entry point particularly effective.
Distributed workforces with high helpdesk interaction rates mean that front-line employees are accustomed to receiving calls from central IT about system updates, credential resets, and connectivity issues. A retail associate who regularly interacts with IT support has little basis to distinguish a legitimate call from a spoofed one, particularly when the caller references real systems and current procedures. The volume of legitimate helpdesk interactions creates a baseline of trust that the attacker exploits, and the distributed nature of the workforce means the caller and the employee will never be in the same building.
These organizations also maintain large Salesforce CRM deployments containing exactly the data BlackFile targets: millions of customer records, employee PII, payment information, and confidential business documents. The combination of an accessible entry point and a high-value exfiltration target makes the sector an efficient choice for a group whose operational model depends on speed. CrowdStrike’s analysis emphasized that both Cordial Spider and Snarky Spider operate at unusual speed, moving from initial access to data exfiltration within hours rather than days, and the SaaS-native approach means they rarely touch the endpoint infrastructure where traditional detection tools operate.
What this reveals about impersonation as an attack chain
The technical reporting on BlackFile has focused, appropriately, on the TTPs: the vishing technique, the device registration bypass, the API-based exfiltration. What has received less attention is the observation that every stage of the operation is an act of impersonation, and none of it depends on the kind of technical exploitation that conventional security tools are built to detect.
The initial access impersonates the IT helpdesk. The phishing page impersonates the organization’s SSO portal. The registered device impersonates a trusted employee endpoint. The API calls impersonate legitimate business activity. And the exfiltrated data, customer contact lists, email templates, internal correspondence, becomes the raw material for potential downstream impersonation of the breached organization’s brand to its own customers.
This is the same progression documented in the ShinyHunters campaign that Unit 42 and Mandiant assessed shares tactical overlap with BlackFile. It mirrors the pattern the university Evilginx campaign used to propagate across 25 institutions from 11 compromised accounts. And it confirms what the crypto impersonation data suggests at a macro level: the most damaging attacks in the current landscape do not exploit code. They exploit identity, and they do so through channels, the phone and the SaaS environment, where the impersonation is hardest to distinguish from the real thing.
For retail and hospitality organizations specifically, the BlackFile campaign makes the case that impersonation defense is not limited to monitoring for external brand abuse. It extends to the internal trust signals that employees rely on every day: the helpdesk number, the SSO portal, the device enrollment process. When those signals can be spoofed without triggering a single technical alert, the defense has to operate at the layer where the impersonation occurs, which increasingly is not the endpoint or the inbox but the phone call and the identity platform.
The Bottom Line
BlackFile has demonstrated that a seven-figure extortion operation can be built entirely on impersonation, without malware, without exploits, and without ever sending a phishing email. The attack chain runs through the phone and the identity platform, two surfaces where the impersonation is hardest to detect and where the signals employees rely on to distinguish legitimate from fraudulent interactions are easiest to spoof. For the retail and hospitality organizations in its crosshairs, the operational lesson is that the same discipline applied to monitoring for external brand impersonation needs to extend inward, to the internal identity surfaces where a phone call that sounds like IT support can open the door to everything the organization holds.
Key Takeaways
A financially motivated extortion group active since at least January 2026, also tracked as CL-CRI-1116, UNC6671, and Cordial Spider. Linked with moderate confidence to The Com, a network of English-speaking young cybercriminals. A companion group, Snarky Spider, uses nearly identical techniques.
The entire attack chain is built on impersonation. Operators call employees from spoofed numbers impersonating IT helpdesk, direct them to fake SSO portals that capture credentials and MFA codes in real time, register attacker-owned devices in Microsoft Entra ID for persistent access, then exfiltrate data from Salesforce and SharePoint using standard API functions.
Distributed workforces with high helpdesk interaction rates make employees accustomed to IT support calls, reducing suspicion. Large Salesforce CRM deployments contain the high-value data the group targets: customer records, employee PII, and confidential business documents.
BlackFile has subjected non-paying victims to DDoS attacks and, in multiple documented cases, SWATting of corporate executives, the practice of reporting fabricated emergencies to trigger armed police responses at their home addresses.
BlackFile demonstrates that impersonation defense extends beyond monitoring for external brand abuse. The internal trust signals employees rely on, including the helpdesk number, the SSO portal, and the device enrollment process, are now attack surfaces. The stolen data from SaaS environments becomes raw material for downstream impersonation of the breached organization’s brand to its customers.



