Helix Group Uses Vishing for SharePoint Data Theft: Ransomware Claim — What’s Alleged & What To Do
On July 9, 2026, Helix Group used vishing to steal files and documents from SharePoint. Check whether your data was exposed and take protective steps if needed.
Reports from July 9, 2026, describe a data-extortion operation in which a group calling itself Helix gained access to SharePoint environments at multiple organizations. The method involved vishing calls, impersonation of managers, device-code phishing, and abuse of multi-factor authentication to register new authenticators and exfiltrate files and documents.
The number of people affected remains unknown, and no confirmed count of compromised records has been released. The incident highlights how cloud collaboration platforms that store internal documents can become targets for extortion when authentication controls are bypassed through social engineering.
What happened
According to the reported summary, operators registered new authenticators on victim accounts, enumerated available files, and removed copies of documents. The activity targeted SharePoint instances across several organizations, with the stated goal of extortion or later sale of the material. No further details on the volume of data, specific victims, or exact timeline of access have been disclosed.
How a breach like this happens
Incidents that begin with vishing typically start with phone calls that impersonate internal staff to obtain credentials or approval for authentication changes. Once initial access is obtained, attackers may abuse device-code flows or MFA fatigue techniques to add their own authenticators. This allows them to maintain persistence and move laterally within cloud storage services without triggering some automated alerts.
After gaining entry, operators often list directory contents, select files of interest, and transfer copies to external locations. The process can occur over days or weeks before the organization detects unusual authenticator registrations or outbound transfers.
Helix Group Uses Vishing for SharePoint Data Theft and its sector
SharePoint environments are commonly used by businesses and institutions to store and share internal documents, project files, and administrative records. Organizations that rely on Microsoft 365 services for collaboration often place sensitive operational material in these repositories because the platform supports version control and access permissions.
When such systems are accessed without authorization, the material removed can include contracts, internal communications, financial worksheets, or personnel-related files. The reported activity indicates that multiple unrelated organizations were approached using similar social-engineering tactics, suggesting the operators are scanning for any accessible SharePoint tenant rather than focusing on a single sector.
What was likely exposed
The only data types named in available reports are files and documents. No inventory of specific file names, categories, or record counts has been published. Organizations that use SharePoint routinely store a wide range of business documents, but the exact contents removed in this case remain unconfirmed.
The real-world impact
Individuals whose information appears in the exfiltrated files may face risks of targeted phishing or identity misuse if the material is later sold or published. Organizations can encounter operational disruption while reviewing access logs, resetting credentials, and responding to extortion demands.
Because the scale of exposure is still unknown, the full extent of downstream consequences for affected people or entities cannot yet be measured.
What to do if you're exposed
Review recent account activity for any unfamiliar authenticator registrations or sign-ins. Change passwords for Microsoft 365 accounts and verify that multi-factor authentication methods are limited to devices you control. Monitor statements and credit reports for unusual activity if personal identifiers may have been present in the documents.
Readers can run a free exposure scan of their email address against known breach data to check whether their information has appeared in previously published lists.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Cushman & Wakefield Data Breach (2026)BH Security (Brinkshome) Listed by ShinyHuntersSBI Software Hit by Genesis Data LeakBri-Tech 588GB Data Leak Claimed by Genesis GroupLatest breaches
Read GalaxyWarden’s full analysis of the Helix Group Uses Vishing for SharePoint Data Theft →
Publicly posted — pending verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.