Ransomware victim disclosure
← All victimsAmSpec LLC
listed as AmSpec · Claimed by Helix · listed 1 day ago
Status timeline
- ListedAug 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Helix
- Status
- Data leaked
- Country
- United States
- Sector
- Energy & Utilities
- Listed on leak site
- Aug 22, 2026
About the victim
AI dossier — public-source company profileAmSpec LLC is an energy and utilities sector company operating multiple regional branches (including St. Croix) and handling hazardous goods logistics. The organization maintains compliance frameworks for EPA regulations, quality management systems, and health, safety, and environmental (HSE) protocols.
- Industry
- Energy & Utilities / Hazardous Materials Logistics
Attack summary
Severity: critical — Confirmed exfiltration of regulatory compliance data (EPA gasoline compliance), operational safety and emergency protocols, hazardous materials shipping records, and laboratory documentation. Energy sector infrastructure data with direct regulatory implications and public safety risk.Helix claims to have exfiltrated SharePoint libraries and sensitive operational data from AmSpec LLC across four tiered release stages. The disclosed data includes compliance documentation, safety protocols, client records, laboratory documents, and hazardous goods shipping information.
Data the group says was taken
AI dossier — extracted from the leak post- Client marketing reports
- Shipping dangerous goods records
- HSE reference documents
- Legal and compliance documentation
- Safety meeting records
- Emergency evacuation plans
- EPA gasoline compliance data
- Quality management system records
- Laboratory documents
- HSSE audit reports
The group's post references roughly 2,359 files in T1 release (1019.2 MB passworded archive); 708,253 files T2; 102,423 files T3; 1,736 files T4 proof files.
What the group claims
AmSpec is live. T1 unlocks on the current 24-hour cadence, then 24 hours per remaining tier.
The leak post
captured from the group's siteTime remaining until this package release unlocks SharePoint libraries · T1 (least) → T4 (most). Stage packages unlock when each timer hits zero. T1 Least → T2 Low → T3 High → T4 Most. T1 · 2,359 files · 1019.2 MB 2 sites in this release AmSpec_T1.7z · 1019.2 MB · passworded .7z T2 · 708,253 files · 0 B Low sensitivity · locked until release 17 sites in this release * Amspecllc / Client Marketing Reports * Amspecllc / Shipping Dangerous Goods * Amspecllc / HSE REFERENCE DOCUMENT LIST * Amspecllc / Legal And ComplianceOldSept2024 * Amspecllc / Monthly Safety Meetings * Amspecllc / HSE Emergency Evacuation Plans * Amspecllc / TICC IFIA Programme * Amspecllc / Global HSSE Audits T3 · 102,423 files · 120.88 GB High sensitivity · locked until release 17 sites in this release * EPACompliance / Gasoline Compliance Data * ARA / Quality Management System * Amspec-St CroixTeamSite / Branch Controlled Laboratory Documents T4 · 1,736 files · 1.02 GB Most sensitivity · locked until release 1 site in this release
Screenshot of the leak post

Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

