:

BLACKFILE EXTORTION GROUP TARGETS RETAIL WITH VISHING ATTACKS

INDUSTRY DESK1 MIN READ
FRI, APR 24, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A new financially motivated hacking group called BlackFile has launched a wave of data theft and extortion attacks against retail and hospitality organizations since February 2026. The group employs vishing tactics to compromise victims.

BlackFile operates as an extortion-focused threat actor, targeting companies in retail and hospitality sectors. The group's attack methodology centers on vishing—voice phishing calls used to socially engineer employees into revealing sensitive information or granting unauthorized access. Once inside networks, BlackFile exfiltrates data and threatens to publish stolen information unless victims pay extortion demands. The campaign has shown consistent targeting patterns and sustained operational activity over several months. Security researchers tracking the group have documented the tactics and infrastructure used in the attacks. Organizations in the affected sectors are advised to implement voice security awareness training and establish protocols for verifying caller identity before granting system access. The emergence of BlackFile reflects broader trends in extortion-based ransomware operations shifting tactics to include social engineering approaches alongside technical exploits.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Security research firms METR and Redwood have published a detailed postmortem examining the HuggingFace security incident. The analysis provides technical insights into how the breach occurred and what systems were compromised.

JUST NOWSecurity Desk

More than a decade of Steam files, including beta builds and finished games from Valve and third-party developers, have been exposed in a major data leak totaling over 12 terabytes.

JUST NOWIndustry Desk

A new vulnerability called Omarchy allows any user-level process to gain root privileges through privilege escalation. The flaw has sparked significant discussion in security circles.

2H AGOIndustry Desk

Hacking group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group. Security researchers confirmed the breach included detailed customer, booking, and travel records.

5H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.