Redact is a cybercrime group that emerged in May 2026, focusing on non-encrypting data extortion following the cessation of BlackFile. It employs sophisticated tactics such as identity compromise, voice phishing, and real-time bypassing of multi-factor authentication to extract sensitive data from high-value corporate targets, primarily in the healthcare, insurance, and financial sectors.
Key insights
•Redact utilizes voice phishing (vishing) to gain initial access and capture user credentials.
•They establish persistence in compromised sessions by registering unauthorized MFA devices.
•Data exfiltration is conducted directly from cloud platforms using native APIs and automated scripts.
•The group pressures victims by publishing stolen data on a Tor-based leak site.
•Target sectors include healthcare, insurance, and financial services within the United States.
•Redact operates as part of a decentralized cybercriminal ecosystem known as The Com.