Ransomware victim disclosure
← All victimsHTHeli
listed as HTHELI.COM · Claimed by Cl0p · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileHTHeli (htheli.com) is an online platform based in China that connects clients with charter helicopter operators globally. The platform offers high-end helicopter services including aerial work, air tours, private hire, VIP charter, and aerial photography. It acts as an aggregator linking users with experienced charter operators across multiple regions.
- Industry
- Luxury Aviation & Helicopter Charter Services
Attack summary
Severity: medium — Data has been published (disclosed status: data_published) by a prolific threat actor (Cl0p), indicating confirmed exfiltration; however, no data volume, regulated data categories, or operational impact details are confirmed, and the leak post content appears AI-generated with low evidentiary value.Cl0p claims to have compromised HTHeli.com and has published data associated with the victim, suggesting exfiltration of company and/or customer data. No ransom amount was stated and no specific data volume was disclosed.
Data the group says was taken
AI dossier — extracted from the leak post- Customer booking records
- Client personal information
- Operator contact details
- Business correspondence
Original description
AI-summarised, not from the leak post"HTHELI.COM" is an online platform dedicated to providing diverse high-end charter helicopter services. They specialize in assisting clients with various helicopter needs, including aerial work, air tours, private hire, VIP charter and aerial photography, among others. The platform connects users with a comprehensive list of experienced and professional charter operators globally.
Sources
- Victim siteHTHELI.COM
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

