LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Helix Group Uses Vishing for SharePoint Data Theft

HIGH severityUnverified claimHow we verify

Helix Group Uses Vishing for SharePoint Data Theft: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 9, 2026
Helix Group Uses Vishing for SharePoint Data Theft

Reported July 9, 2026.

HIGH
Severity
2
Data types exposed
July 9, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On July 9, 2026, Helix Group used vishing to steal files and documents from SharePoint. Check whether your data was exposed and take protective steps if needed.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Lede paragraphs first.

Reports from July 9, 2026, describe a data-extortion operation in which a group calling itself Helix gained access to SharePoint environments at multiple organizations. The method involved vishing calls, impersonation of managers, device-code phishing, and abuse of multi-factor authentication to register new authenticators and exfiltrate files and documents.

The number of people affected remains unknown, and no confirmed count of compromised records has been released. The incident highlights how cloud collaboration platforms that store internal documents can become targets for extortion when authentication controls are bypassed through social engineering.

What happened

According to the reported summary, operators registered new authenticators on victim accounts, enumerated available files, and removed copies of documents. The activity targeted SharePoint instances across several organizations, with the stated goal of extortion or later sale of the material. No further details on the volume of data, specific victims, or exact timeline of access have been disclosed.

How a breach like this happens

Incidents that begin with vishing typically start with phone calls that impersonate internal staff to obtain credentials or approval for authentication changes. Once initial access is obtained, attackers may abuse device-code flows or MFA fatigue techniques to add their own authenticators. This allows them to maintain persistence and move laterally within cloud storage services without triggering some automated alerts.

After gaining entry, operators often list directory contents, select files of interest, and transfer copies to external locations. The process can occur over days or weeks before the organization detects unusual authenticator registrations or outbound transfers.

Helix Group Uses Vishing for SharePoint Data Theft and its sector

SharePoint environments are commonly used by businesses and institutions to store and share internal documents, project files, and administrative records. Organizations that rely on Microsoft 365 services for collaboration often place sensitive operational material in these repositories because the platform supports version control and access permissions.

When such systems are accessed without authorization, the material removed can include contracts, internal communications, financial worksheets, or personnel-related files. The reported activity indicates that multiple unrelated organizations were approached using similar social-engineering tactics, suggesting the operators are scanning for any accessible SharePoint tenant rather than focusing on a single sector.

What was likely exposed

The only data types named in available reports are files and documents. No inventory of specific file names, categories, or record counts has been published. Organizations that use SharePoint routinely store a wide range of business documents, but the exact contents removed in this case remain unconfirmed.

The real-world impact

Individuals whose information appears in the exfiltrated files may face risks of targeted phishing or identity misuse if the material is later sold or published. Organizations can encounter operational disruption while reviewing access logs, resetting credentials, and responding to extortion demands.

Because the scale of exposure is still unknown, the full extent of downstream consequences for affected people or entities cannot yet be measured.

What to do if you're exposed

Review recent account activity for any unfamiliar authenticator registrations or sign-ins. Change passwords for Microsoft 365 accounts and verify that multi-factor authentication methods are limited to devices you control. Monitor statements and credit reports for unusual activity if personal identifiers may have been present in the documents.

Readers can run a free exposure scan of their email address against known breach data to check whether their information has appeared in previously published lists.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Method

More recent breaches

Cushman & Wakefield Data Breach (2026)May 5, 2026BH Security (Brinkshome) Listed by ShinyHuntersJuly 27, 2026SBI Software Hit by Genesis Data LeakJuly 6, 2026Bri-Tech 588GB Data Leak Claimed by Genesis GroupJuly 3, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Helix Group Uses Vishing for SharePoint Data Theft →

Source: BleepingComputer

Publicly posted — pending verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram