Cyber Security Published on July 9, 2026
Helix vishing group emerges, targets SharePoint data theft
ReliaQuest disclosed a new data extortion group named Helix.
Operators impersonate managers during voice phishing calls to trick employees into device code authentication flows.
Once inside, they register a new MFA authenticator and bulk-download SharePoint files for extortion.
Researchers link Helix infrastructure and tactics to the ShinyHunters and BlackFile ecosystems.
Source: BleepingComputer