{"id":60798,"date":"2026-06-04T22:16:55","date_gmt":"2026-06-04T22:16:55","guid":{"rendered":"https:\/\/www.theregister.com\/a\/5251434"},"modified":"2026-06-04T22:16:55","modified_gmt":"2026-06-04T22:16:55","slug":"pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/","title":{"rendered":"Pink is the latest goon squad to use fake helpdesk calls to steal creds"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/5251457.jpg?imageId=5251457&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" class=\"ff-og-image-inserted\"><\/div>\n<div data-element-guid=\"d11159dd-82a3-4c53-901c-d41dec75505c\" readability=\"30.947368421053\">\n<p class=\"kicker \">CYBER-CRIME<\/p>\n<p class=\"subtitle t21\">A familiar tactic popularized by chaotic crime crew Lapsus$<\/p>\n<\/p><\/div>\n<div data-element-guid=\"4c9dc5d9-c886-4348-bf4a-01d0dc71377d\" readability=\"128.69647058824\">\n<p><span class=\"font-weight-bold m-font-weight-bold tertiary color_mobile_tertiary\" data-lab-font_weight=\"font-weight-bold\" data-lab-text_color=\"tertiary\">UPDATED<\/span><span class=\"font-weight-bold m-font-weight-bold\" data-lab-font_weight=\"font-weight-bold\">&nbsp;<\/span>A new extortion brand called Pink \u2013 which may be a rebrand of BlackFile \u2013 uses voice phishing and fake help-desk calls to gain initial access to organizations\u2019 IT environments, steal their sensitive data, and threaten to leak it unless the victims pay a ransom demand.<\/p>\n<p>Palo Alto Networks&#8217; Unit 42 first spotted the gang, which it tracks as cluster CL-CRI-1147, and its data-leak site, which went live on May 31. \u201cPink uses vishing and IT impersonation to phish credentials\/MFA, then exfiltrates enterprise cloud storage and productivity data to extort victims,\u201d the threat-intelligence biz <a href=\"https:\/\/www.linkedin.com\/posts\/we-are-tracking-pink-cl-cri-1147-a-new-ugcPost-7467982449772429312-qcbZ\/\" rel=\"nofollow\">said<\/a> in a LinkedIn post.<\/p>\n<p>Google Threat Intelligence is not so sure it&#8217;s a new gang, however. <\/p>\n<p>&#8220;After retiring the BlackFile brand in May 2026, we assess the group launched the &#8216;Redact&#8217; brand and has now potentially surfaced as &#8216;Pink,,&#8221; Austin Larsen, Principal Threat Analyst at Google Threat Intelligence Group, told us. &#8220;This new operation exhibits hallmarks of UNC6671, including similar credential-harvesting infrastructure, data leak site (DLS), and recurring messaging that claims to &#8216;improve the security&#8217; of victims who pay. Additionally, we attribute the Pink (CL-CRI-1147) domains recently published by Unit42 to UNC6671.&#8221;<\/p>\n<p>Regardless whether it&#8217;s brand new or just a new coat of paint, the tactics are very familiar.&nbsp; Pink is one of many&nbsp;<a href=\"https:\/\/www.theregister.com\/security\/2025\/08\/12\/three-notorious-cybercrime-gangs-appear-to-be-collaborating\/393646\">goon squads<\/a>&nbsp;to use these <a href=\"https:\/\/www.theregister.com\/special-features\/2026\/03\/23\/voice-phishing-skyrockets-as-smooth-crims-talk-their-way-in\/5223759\">social-engineering tactics<\/a> to steal employees\u2019 credentials and bypass multi-factor authentication, using this access to burgle companies\u2019 cloud storage and databases.&nbsp;<\/p>\n<p>Chaotic crime crew Lapsus$, during its 2021 and 2022 extortion spree that hit <a href=\"https:\/\/www.theregister.com\/2022\/02\/26\/nvidia_security_breach\/\">Nvidia<\/a>, <a href=\"https:\/\/www.theregister.com\/2022\/03\/21\/microsoft_lapsus_breach_probe\/\">Microsoft<\/a>, and <a href=\"https:\/\/www.theregister.com\/2022\/03\/23\/olkta_microsoft_lapsus\/\">Okta<\/a>, among others, popularized this style of phone-based intrusions before <a href=\"https:\/\/www.theregister.com\/security\/2025\/05\/18\/ex-nsa-listened-to-scattered-spiders-calls-theyre-good\/801296\">Scattered Spider<\/a> picked up the mantle. Scattered Spider is perhaps best known for its 2023 <a href=\"https:\/\/www.theregister.com\/security\/2023\/12\/28\/do-the-casino-ransomware-attacks-make-the-case-to-pay\/580707\">Las Vegas casino digital heists<\/a>, and reportedly bragged that all it took to break into MGM&#8217;s networks was a 10-minute call with the help desk.<\/p>\n<p>Over the last few years, ShinyHunters has used this same playbook to steal sensitive data from <a href=\"https:\/\/www.theregister.com\/security\/2024\/05\/30\/crooks-steal-560m-peoples-info-from-ticketmaster\/1059565\">Ticketmaster,<\/a> <a href=\"https:\/\/www.theregister.com\/security\/2025\/06\/05\/att-investigates-claimed-sale-of-70m-customer-data-dump\/538763\">AT&amp;T<\/a>, and <a href=\"https:\/\/www.theregister.com\/security\/2026\/03\/09\/shinyhunters-claims-yet-another-salesforce-customers-breach\/5220118\">other Salesforce customers<\/a>, and <a href=\"https:\/\/www.theregister.com\/cyber-crime\/2026\/05\/14\/security-pros-doubt-canvas-attackers-really-deleted-stolen-student-data\/5240799\">thousands of schools and universities<\/a> that use Canvas\u2019 digital learning platform.<\/p>\n<p>Despite <a href=\"https:\/\/www.theregister.com\/security\/2025\/09\/15\/15-ransomware-gangs-go-dark-to-enjoy-golden-parachutes\/1080583\">multiple arrests<\/a> across all three gangs, they keep coming back to victimize more organizations. Most incident responders, including Google\u2019s Mandiant and Unit 42, link many of<span>&nbsp;<\/span>these criminal collectives to <a href=\"https:\/\/www.theregister.com\/security\/2025\/07\/23\/irl-com-recruits-teens-for-real-life-stabbings-shootings\/1258543\">The Com<\/a>, a loosely knit group of primarily English speakers made up of several interconnected networks of hackers, SIM swappers, and extortionists, with some of its subgroups offering real-life violent crime for hire.<\/p>\n<p>According to Unit 42, this latest cluster of extortion activity is also \u201clikely a Com-affiliated actor.\u201d And after investigating \u201cmultiple\u201d of these extortion attacks over the past few months, on Monday, they spotted something that led them to Pink\u2019s name-and-shame website.<\/p>\n<p>\u201cOn June 1, 2026, an existing extortion negotiation that had never received a response, attributed to a likely Com-related cluster, received new communication from a threat actor via a free webmail account,\u201d Unit 42 analysts Richard Emerson and Cuong Dinh <a href=\"https:\/\/github.com\/PaloAltoNetworks\/Unit42-timely-threat-intel\/blob\/main\/2026-06-03-Pink-Extortion-Brand-Activity.txt?utm_campaign=tti_pinkextortion\" rel=\"nofollow\">said<\/a> in a Wednesday threat-intel post. \u201cThe actor provided a new qTox ID and a leak site associated with the Pink brand, but referenced exfiltrating almost identical information from the original extortion notice.\u201d<\/p>\n<p>Pink data thieves set a 72-hour deadline for the victim to respond before leaking the stolen goods.<\/p>\n<p>After gaining access to the victim\u2019s account, the criminals snoop around for valuable corporate and customer data from platforms like SharePoint and OneDrive. After exfiltrating the stolen files, Pink attackers use compromised victim accounts and internal Teams messages to extort the company.<\/p>\n<p>\u201cThe actor reuses second-level domains to target multiple organizations, and the third-level domain typically thematically represents the target,\u201d Emerson and Dinh wrote.<\/p>\n<p>They also listed the following phishing domains as indicators of compromise:&nbsp;<\/p>\n<ul>\n<li>\n<p>passkeyadd[.]com<\/p>\n<\/li>\n<li>\n<p>passkeydeploy[.]com<\/p>\n<\/li>\n<li>\n<p>deploypasskey[.]com<\/p>\n<\/li>\n<\/ul>\n<p>Along with these three IP addresses:<\/p>\n<ul readability=\"0\">\n<li readability=\"-1\">\n<p>185[.]178.208[.]153 (hosted phishing domains)<\/p>\n<\/li>\n<li readability=\"-1\">\n<p>172[.]93.100[.]252 (accessed compromised accounts)<\/p>\n<\/li>\n<li readability=\"-1\">\n<p>96[.]232.20[.]66 (residential proxy IP responsible for extortion email creation)<\/p>\n<\/li>\n<\/ul>\n<div data-element-guid=\"afe083ca-6701-48e9-9bd8-f8827dd7fb42\" class=\"lab4 column articleList layout_vertical imageLayout_left small-12 large-12 small-abs-12 large-abs-12 abs_grid_12 grid-vas-start mobile-grid-vas-start\">\n<div class=\"content border_width_0 border_width_mobile_0 border-radius-48 border-radius-mobile_48\">\n<h2 class=\"article-list-title t19 font-RobotoCondensed\">MORE CONTEXT<\/h2>\n<\/p><\/div>\n<\/div>\n<p>Plus, these user-agent strings were observed during data exfiltration:<\/p>\n<p>Network defenders can use these to assist in threat-hunting efforts. And be very wary of help desk calls, both from people claiming to be employees locked out of corporate accounts and from those purporting to be support staff rolling out a mandatory MFA update or other emergency. \u00ae<\/p>\n<\/p><\/div>\n<p><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/?imageId=5251457&#038;width=800\">READ MORE <a href=\"https:\/\/www.theregister.com\/cyber-crime\/2026\/06\/04\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/5251434\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> A familiar tactic popularized by chaotic crime crew Lapsus$ READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":60799,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[1047],"class_list":["post-60798","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register","tag-cyber-crime"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Pink is the latest goon squad to use fake helpdesk calls to steal creds 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Pink is the latest goon squad to use fake helpdesk calls to steal creds 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-04T22:16:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/image.theregister.com\/5251457.jpg?imageId=5251457&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Pink is the latest goon squad to use fake helpdesk calls to steal creds\",\"datePublished\":\"2026-06-04T22:16:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\\\/\"},\"wordCount\":719,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds.jpg\",\"keywords\":[\"Cyber Crime\"],\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\\\/\",\"name\":\"Pink is the latest goon squad to use fake helpdesk calls to steal creds 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds.jpg\",\"datePublished\":\"2026-06-04T22:16:55+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds.jpg\",\"width\":100,\"height\":68},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyber Crime\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/cyber-crime\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Pink is the latest goon squad to use fake helpdesk calls to steal creds\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Pink is the latest goon squad to use fake helpdesk calls to steal creds 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/","og_locale":"en_US","og_type":"article","og_title":"Pink is the latest goon squad to use fake helpdesk calls to steal creds 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-06-04T22:16:55+00:00","og_image":[{"url":"https:\/\/image.theregister.com\/5251457.jpg?imageId=5251457&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Pink is the latest goon squad to use fake helpdesk calls to steal creds","datePublished":"2026-06-04T22:16:55+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/"},"wordCount":719,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/06\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds.jpg","keywords":["Cyber Crime"],"articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/","url":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/","name":"Pink is the latest goon squad to use fake helpdesk calls to steal creds 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/06\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds.jpg","datePublished":"2026-06-04T22:16:55+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/06\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/06\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds.jpg","width":100,"height":68},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cyber Crime","item":"https:\/\/www.threatshub.org\/blog\/tag\/cyber-crime\/"},{"@type":"ListItem","position":3,"name":"Pink is the latest goon squad to use fake helpdesk calls to steal creds"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60798","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=60798"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60798\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/60799"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=60798"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=60798"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=60798"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}