Ransomware victim disclosure
← All victimsHTHeli
listed as HTHELI.COM · Claimed by Clop · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileHTHeli (htheli.com) appears to be a helicopter services company based in China, as indicated by the domain and country attribution. The company likely provides helicopter charter, tourism, or related aviation services. No additional verified details are available from the public site or leak post.
- Industry
- Helicopter Charter & Aviation Services
Attack summary
Severity: medium — Data is listed as published by Clop, a group known for mass exfiltration campaigns, but no proof files, data inventory, or operational impact details are visible from the leak post. The disclosed status implies exfiltration rather than encryption-only, warranting at least medium severity, but lack of any verifiable proof or data description prevents a higher rating.The Clop ransomware group has listed HTHELI.COM as a victim with a disclosed status of 'data_published', suggesting data exfiltration has occurred; however, the leak post content is uninformative (a redirect queue page) and no specific data types or volumes are described.
Original description
AI-summarised, not from the leak post"HTHELI.COM" is an online platform dedicated to providing diverse high-end charter helicopter services. They specialize in assisting clients with various helicopter needs, including aerial work, air tours, private hire, VIP charter and aerial photography, among others. The platform connects users with a comprehensive list of experienced and professional charter operators globally.
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

