Skip to main content

Ransomware victim disclosure

All victims

Highwoods Properties

Claimed by HELIX · listed 5 days ago

~90+ GB across released packages
Data size
13463 files records
5d
Age
since listed · data leaked

Status timeline

  1. ListedAug 13, 2026
  2. Data leakeddate unknown

At a glance

Group
HELIX
Status
Data leaked
Listed on leak site
Aug 13, 2026
Data size
~90+ GB across released packages
Records
13463 files

About the victim

AI dossier — public-source company profile

Highwoods Properties is a real estate company with operations spanning multiple markets including Nashville. The organization maintains significant property management and marketing infrastructure across multiple sites and development projects.

Industry
Real Estate & Property Management

Attack summary

Severity: high — Confirmed exfiltration and publication of 90+ GB of business data including internal communications, property management information, development documents, and enterprise directory. Multi-staged release demonstrates operational capacity and intent to maximize exposure.

HELIX claims to have exfiltrated approximately 90+ GB of data from Highwoods Properties, including SharePoint libraries, email systems, property management records, development documents, and marketing materials. Data is being released in staged tiers (T1–T4) on the group's leak board.

high

Data the group says was taken

AI dossier — extracted from the leak post
  • SharePoint libraries
  • Email messages and attachments
  • Property management records
  • Development documents
  • Marketing materials
  • Internal site data
  • Entra identity directory

The group's post references roughly 21+ downloadable packages across multiple tiers proof files.

What the group claims

Highwoods Properties is a victim listed on the Helix ransomware leak board. Exfiltrated data is organized in SharePoint libraries across sensitivity tiers (T1-T4), including construction documents, property management files, marketing materials, mailbox emails and attachments, and energy insight data across multiple markets including Nashville.

The leak post

captured from the group's site
- Company leak board for Highwoods Properties. This is the destination link from Helix Leaks. Countdown until releases; later stages unlock on schedule. Entra + inventory visible; downloads follow each stage. 
# Stage 04 · Construction & Energy
Time remaining until this stage unlocks on the company leak board
## Highwoods Properties · Sensitivity layers
SharePoint libraries · T1 (least) → T4 (most). Stage packages unlock when each timer hits zero.
T1 Least → T2 Low → T3 High → T4 Most. 
T1 Other Small Sites T1 · 975.9 MB
Classified package ready 
[ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T1/Other_Small_Sites_T1/part-001.zip)
T2 Other Small Sites T2 · 1.97 GB
Classified package ready 
[ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T2/Other_Small_Sites_T2/part-001.zip)
T2 Mailbox Attachments · 1.72 GB
Classified package ready 
[ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T2/Mailbox_Attachments/part-001.zip)
T2 Mailbox Emails · 152.6 MB
Classified package ready 
[ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onio…

Data the group says was taken

  • SharePoint libraries
  • construction documents
  • property management files
  • marketing materials
  • mailbox emails
  • mailbox attachments
  • energy insight data
  • development documents

Screenshot of the leak post

Leak screenshot for Highwoods Properties

Sources

Source

Indexed 5 days ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About HELIX

HELIX is an active ransomware group with 10 confirmed victims as of August 2026, operating one onion leak site. The small victim tally points to either a recent entry or selective targeting. The group has been linked to 18 public disclosures across our corpus. The operation is currently active.

Timeline of this disclosure

  • August 13, 2026Highwoods Properties listed by HELIXon the group's public leak site
Data size
~90+ GB across released packages
Records
13463 files

Sector and geography

This disclosure adds to ransomware activity in the Real Estate sector, which has 91 disclosures indexed across all operators we track.

If your organisation is affected

A listing by HELIX means Highwoods Properties appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Monitor for the data appearing on HELIX's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.