Ransomware victim disclosure
← All victimsMorguard Corporation
listed as Morguard · Claimed by HELIX · listed 3 hours ago
Status timeline
- ListedAug 10, 2026
Current state: Negotiating
At a glance
- Group
- HELIX
- Status
- Negotiating
- Listed on leak site
- Aug 10, 2026
About the victim
AI dossier — public-source company profileMorguard is a Canadian real estate investment and management company. Without access to their public site, the exact scale and headquarters location cannot be confirmed from the leak post alone.
- Industry
- Real Estate & Property Management
Attack summary
Severity: high — Confirmed exfiltration of corporate data (SharePoint libraries) from a large real estate firm; staged release threat with active countdown indicates operational leverage and significant business data at risk. No regulated PII confirmation lowers from critical, but scale and nature of business data elevates to high.HELIX claims to have exfiltrated data from Morguard's SharePoint libraries, staged across four tiers (T1–T4). The group states Morguard engaged in negotiation but failed to meet deadlines or provide serious ransom offers, and now threatens gradual public release on a countdown timer.
Data the group says was taken
AI dossier — extracted from the leak post- SharePoint libraries
- Corporate documents
What the group claims
Morguard reached out, took extensions, then ignored the negotiation with no real offer. Contacting us and stalling is not a strategy. Deadlines stand. Silence after outreach gets a private board and a countdown then publication.
The leak post
captured from the group's sitePublished feeds. Opening a feed leaves this site for the board onion. [ Westland reached out, got the full demand, then stalled with no serious number. Contacting us and dragging process is not negotiation. ](http://helix2kvkqjzrkh3ospyukij7uemxwvbdmqberjmrudjmqy4hspwzzqd.onion/p/380506d310d5417b836512938f95a302a7fb021fbe54b9f392da079aaf9ade1e) [ Morguard reached out, took extensions, then ignored the negotiation with no real offer. Contacting us and stalling is not a strategy. Deadlines stand. Silence after outreach gets a private board and a countdown then publication. ](http://helix2kvkqjzrkh3ospyukij7uemxwvbdmqberjmrudjmqy4hspwzzqd.onion/p/c986586defd4792920f696b167ebdef91eca624746fe6cb5c6a06a0661e43d09) [ SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0. ](http://helix2kvkqjzrkh3ospyukij7uemxwvbdmqberjmrudjmqy4hspwzzqd.onion/p/0194658fe7e20d85cecdfb41e2e7545b5d60ac3a53314ecc52c0e239ac6e912c) [ SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0. ](http://helix2kvkqjzrkh3ospyukij7uemxwvbdmqberjmrudjmqy4hspwz…
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

