Ransomware victim disclosure
← All victimsHighwoods Properties
Claimed by Helix · listed 1 day ago
Status timeline
- ListedAug 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Helix
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Aug 7, 2026
About the victim
AI dossier — public-source company profileHighwoods Properties is a publicly traded real estate company that owns and manages office, retail, and medical properties across multiple US markets including Atlanta, Charlotte, Dallas, Nashville, Orlando, Pittsburgh, Raleigh, Richmond, and Tampa. The company operates a portfolio of commercial real estate assets and provides property management services.
- Industry
- Real Estate & Property Management
Attack summary
Severity: medium — Data exfiltration confirmed (SharePoint staging) with tiered release mechanism announced, but no specific sensitive data types or scale clarified in the leak post. Real estate/property company data is lower sensitivity than regulated sectors, though tenant/client information could be at stake.The Helix ransomware group claims to have exfiltrated data from Highwoods Properties, staging SharePoint libraries in tiers (T1-T4) with a countdown timer for incremental disclosure. The post indicates a tiered data release strategy but provides no specific details on data types or volume.
Data the group says was taken
AI dossier — extracted from the leak post- SharePoint documents
- Business files
What the group claims
SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0.
Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

