UNC6783 Breaches BPO Providers to Target Adobe and Other Companies for Extortion
Business process outsourcing providers often have access to clients' customer service systems, accounts and internal data. Once compromised, attackers can exploit trusted identities to infiltrate multiple companies. Google Threat Intelligence Group (GTIG) classifies UNC6783 as a financially motivated threat actor. Its targeting of high-value organizations including Adobe highlights third-party supply chains as a critical weakness in enterprise identity security.
GTIG disclosed on April 7, 2026, that UNC6783 had targeted dozens of high-value companies across multiple industries. The group used live chats to direct victims to fake Okta pages, captured clipboard contents to bypass MFA and registered its own devices to maintain access. A hacker known as Mr. Raccoon separately claimed to have stolen about 13 million Adobe customer-support tickets and data on 15,000 employees from an Indian BPO provider. Adobe has not confirmed the claim, and the ransom amount has not been disclosed.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.