Ransomware victim disclosure
← All victimsMorguard Corporation
listed as Morguard · Claimed by Helix · listed 1 day ago
Status timeline
- ListedAug 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Helix
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Aug 7, 2026
About the victim
AI dossier — public-source company profileMorguard Corporation is a fully integrated real estate platform with $24.2 billion in total asset value. The company acquires, develops, owns and manages multi-suite residential, commercial and hotel properties across North America, and operates as a premier real estate investment advisor and management company with operations spanning Canada and the United States.
- Industry
- Real Estate Investment, Management & Advisory
- Address
- 60 Bloor Street West, Toronto, ON, Canada
- Founded
- 1976
Attack summary
Severity: high — Confirmed data publication by ransomware operator against a major real estate corporation managing $24.2B in assets. Large-scale exfiltration of business-sensitive data (property portfolios, corporate records) poses significant operational and reputational risk, though no regulated PII or financial data specificity is detailed in the post.The Helix group claims to have compromised Morguard and threatened publication of exfiltrated data. After initial contact and negotiation extension requests, Morguard reportedly went silent, prompting the group to announce data publication.
Data the group says was taken
AI dossier — extracted from the leak post- corporate communications
- business records
- property/portfolio data
What the group claims
Morguard reached out, took extensions, then ignored the negotiation with no real offer. Contacting us and stalling is not a strategy. Deadlines stand. Silence after outreach gets a private board and a countdown then publication.
Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

