Ransomware victim disclosure
← All victimsAmSpec
Claimed by HELIX · listed 21 hours ago
Status timeline
- ListedAug 23, 2026
Current state: Listed for ransom
At a glance
- Group
- HELIX
- Status
- Listed for ransom
- Listed on leak site
- Aug 23, 2026
- Data size
- 1019.2 MB
- Records
- 2359 files
About the victim
AI dossier — public-source company profileAmSpec is a company that has been listed as a victim in a ransomware disclosure by the HELIX group. Limited public information is available from the leak post itself.
Attack summary
Severity: medium — Confirmed exfiltration of business data (SharePoint libraries) with staged release, but no specific data types (PII, financial, medical) are explicitly named in the post. The 1019.2 MB data size and tiered release mechanism indicate moderate operational significance, but sensitivity level is unclear.The HELIX group claims to have exfiltrated data from AmSpec, with stolen content staged in SharePoint libraries across four tiers (T1–T4). Data is being released on a time-locked cadence, with T1 unlocking on a 24-hour cycle and subsequent tiers following at 24-hour intervals per tier.
Data the group says was taken
AI dossier — extracted from the leak post- SharePoint libraries
- business documents
What the group claims
AmSpec is live. T1 unlocks on the current 24-hour cadence, then 24 hours per remaining tier.
The leak post
captured from the group's sitePublished feeds. Opening a feed leaves this page for the board. [ AmSpec is live. T1 unlocks on the current 24-hour cadence, then 24 hours per remaining tier. · Operator · Board live ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/05d7e14bd3e7d7efce2406aad744dc6daa15edfbca7d38cb8ced622125d3c989) [ Delek US is live. T1 unlocks in 12 hours, then 24 hours per remaining tier. · Operator · Board live ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/169f107db2a3ef002d03c665c3adf1f71560d1c5463ef35f720a9d5062f80d4b) [ Kennedy Jenks is live. T1–T3 are unlocked. T4 in 24 hours. · Operator · Board live ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/1ba8b0df41a617631d09ae43a2bb4a5748b5b3f2b1cd007251bb3598a5ddcf44) [ Westland reached out, got the full demand, then stalled with no serious number. Contacting us and dragging process is not negotiation. · Operator · Board live ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/380506d310d5417b836512938f95a302a7fb021fbe54b9f392da079aaf9ade1e) [ Morguard reached out, took extensions, then ignored the negotiation with no real offer. Contacting us and s…
Screenshot of the leak post

Sources
Source
Indexed 21 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

