Alex Yao Alex Yao
Back to news
Cyber Security Published on July 9, 2026

Helix vishing group emerges, targets SharePoint data theft

ReliaQuest disclosed a new data extortion group named Helix.

Operators impersonate managers during voice phishing calls to trick employees into device code authentication flows.

Once inside, they register a new MFA authenticator and bulk-download SharePoint files for extortion.

Researchers link Helix infrastructure and tactics to the ShinyHunters and BlackFile ecosystems.