---
title: BlackFile Group Targets Retail and Hospitality with Vishing Attacks
metaTitle: BlackFile Group Targets Retail & Hospitality
description: BlackFile, a vishing-driven extortion group, is targeting retail and hospitality via credential phishing, and demanding seven-figure ransoms.
slug: blackfile-group-targets-retail-and-hospitality
date: "2026-04-27T12:00:00-05:00"
featured: true
image:
  src: "https://cdn.securelogix.dev/slx/images/blackfile-group-hooked-fish.webp"
  alt: "A fish flapping on a hook."
sourcePublisher:
  name: Infosecurity Magazine
  url: "https://www.infosecurity-magazine.com/"
sourceArticle:
  url: "https://www.infosecurity-magazine.com/news/blackfile-group-targets-retail/"
tags: [Vishing, Spoofing, SSO, Tech Support Scam]
status: published
---

Security researchers have revealed details of a new extortion group that has been actively targeting retail and hospitality businesses since February 2026.

Palo Alto Networks’ Unit 42 teamed up with the Retail and Hospitality Information Security and Analysis Center (RH-ISAC) to publish a new report on April 23, Extortion in the Enterprise: Defending Against BlackFile Attacks.

It detailed financially-motivated activity linked to the activity cluster CL-CRI-1116, which the authors said overlaps with public reporting on BlackFile, UNC6671 and Cordial Spider, and is likely to be associated with notorious collective “The Com...”
