Mark RadarMARK RADAR
EN
Event File FINTECH Supply Chain Attacks

UNC6783 Breaches BPO Providers to Target Adobe and Other Companies for Extortion

1 reports · First detected 2026-04-09 · Last active 2026-04-09

Business process outsourcing providers often have access to clients' customer service systems, accounts and internal data. Once compromised, attackers can exploit trusted identities to infiltrate multiple companies. Google Threat Intelligence Group (GTIG) classifies UNC6783 as a financially motivated threat actor. Its targeting of high-value organizations including Adobe highlights third-party supply chains as a critical weakness in enterprise identity security.

GTIG disclosed on April 7, 2026, that UNC6783 had targeted dozens of high-value companies across multiple industries. The group used live chats to direct victims to fake Okta pages, captured clipboard contents to bypass MFA and registered its own devices to maintain access. A hacker known as Mr. Raccoon separately claimed to have stolen about 13 million Adobe customer-support tickets and data on 15,000 employees from an Indian BPO provider. Adobe has not confirmed the claim, and the ransom amount has not been disclosed.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)