Ransomware victim disclosure
← All victimsKennedy/Jenks
listed as Kennedy Jenks · Claimed by HELIX · listed 2 days ago
Status timeline
- ListedAug 16, 2026
- Data leakeddate unknown
At a glance
- Group
- HELIX
- Status
- Data leaked
- Listed on leak site
- Aug 16, 2026
- Data size
- 2.39 GB
- Records
- 1389 files
About the victim
AI dossier — public-source company profileKennedy/Jenks is an engineering and consulting firm. Limited information is available from the leak post alone.
- Industry
- Engineering & Consulting
Attack summary
Severity: high — Confirmed exfiltration of significant business data (2.39 GB from SharePoint libraries); staged multi-tier release indicates sensitive material. No proof files/screenshots are advertised in the truncated post, but the disclosed status is 'data_published' and tier-based release is live.HELIX claims to have exfiltrated data from Kennedy/Jenks, staging SharePoint libraries in four tiers with progressive public release. The group states negotiation contact was made but stalled; no payment demand figure is stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- SharePoint libraries
- Business documents
What the group claims
T1 is unlocked. T2 in 24 hours, then one day each through T4. SharePoint libraries staged T1 (least) to T4 (most). Release countdown live on Helix.
The leak post
captured from the group's sitePublished feeds. Opening a feed leaves this page for the board. [ Kennedy Jenks is live. T1 is unlocked. T2 in 24 hours, then one day each through T4. · Operator · Board live ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/1ba8b0df41a617631d09ae43a2bb4a5748b5b3f2b1cd007251bb3598a5ddcf44) [ Westland reached out, got the full demand, then stalled with no serious number. Contacting us and dragging process is not negotiation. · Operator · Board live ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/380506d310d5417b836512938f95a302a7fb021fbe54b9f392da079aaf9ade1e) [ Morguard reached out, took extensions, then ignored the negotiation with no real offer. Contacting us and stalling is not a strategy. Deadlines stand. Silence after outreach gets a private board and a countdown then publication. · Operator · Board live ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/c986586defd4792920f696b167ebdef91eca624746fe6cb5c6a06a0661e43d09) [ SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0. · Operator · Board live ](http://helixr2sncrd3nds…
Data the group says was taken
- SharePoint libraries
Screenshot of the leak post

Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

