Skip to main content

Ransomware victim disclosure

All victims

Westland Insurance

Claimed by HELIX · listed 5 days ago

249.32 GB
Data size
796742 files records
5d
Age
since listed · data leaked

Status timeline

  1. ListedAug 13, 2026
  2. Data leakeddate unknown

At a glance

Group
HELIX
Status
Data leaked
Sector
Insurance
Listed on leak site
Aug 13, 2026
Data size
249.32 GB
Records
796742 files

About the victim

AI dossier — public-source company profile

Westland Insurance is an insurance company operating with enterprise infrastructure including SharePoint, email systems, IT/development environments, and accounts receivable/payable operations. Scale and specific service lines are not publicly confirmed.

Industry
Insurance

Attack summary

Severity: critical — Confirmed exfiltration of 249.32 GB across 521+ files at high sensitivity (AR/AP, billing, broker/carrier intelligence, IT systems, email). Insurance sector data typically includes PII (customer names, policy numbers, claims history) and financial records; staged release by group with password-protected archives demonstrates operational access and intent to distribute.

HELIX claims to have exfiltrated 249.32 GB of data from Westland Insurance across four sensitivity tiers (T1–T4), including email, IT/development systems, billing records, and broker/carrier documentation. Data is staged for scheduled release with passworded archive files.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • Email archives (legacy & bulk)
  • IT infrastructure documentation
  • Development/web application source or configuration
  • Accounts receivable records
  • Accounts payable records
  • Billing data
  • Broker communications
  • Carrier documentation
  • MGA (Managing General Agent) records
  • SharePoint libraries

What the group claims

Westland Insurance data leaked in tiered stages via SharePoint libraries with sensitivity layers T1 through T4 (least to most sensitive). Stages include Email/Legacy/Bulk, IT/Dev/Web, AR/AP/Billing, Broker/Carrier/MGA, and 11 additional sites.

The leak post

captured from the group's site
- Company leak board for Westland Insurance. This is the destination link from Helix Leaks. Countdown until releases; later stages unlock on schedule. Entra + inventory visible; downloads follow each stage. 
## Westland Insurance · Sensitivity layers
SharePoint libraries · T1 (least) → T4 (most). Stage packages unlock when each timer hits zero.
T1 Least → T2 Low → T3 High → T4 Most. 
T1 · 359,098 files · 30.14 GB
4 sites in this release
  * Email — Legacy & Bulk


Westland_T1.7z · 30.14 GB · passworded .7z
T2 · 85,822 files · 88.41 GB
5 sites in this release
  * IT / Dev / Web


Westland_T2.7z · 88.41 GB · passworded .7z
T3 · 76,309 files · 15.32 GB
4 sites in this release
  * AR / AP / Billing
  * Broker / Carrier / MGA


Westland_T3.7z · 15.32 GB · passworded .7z
T4 · 275,513 files · 115.45 GB
11 sites in this release


Westland_T4.7z · 115.45 GB · passworded .7z

Data the group says was taken

  • emails
  • SharePoint documents
  • IT/development files
  • web files
  • accounts receivable
  • accounts payable
  • billing records
  • broker records
  • carrier records
  • MGA records
  • inventory

Screenshot of the leak post

Leak screenshot for Westland Insurance

Sources

Source

Indexed 5 days ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About HELIX

HELIX is an active ransomware group with 10 confirmed victims as of August 2026, operating one onion leak site. The small victim tally points to either a recent entry or selective targeting. The group has been linked to 18 public disclosures across our corpus. The operation is currently active.

Timeline of this disclosure

  • August 13, 2026Westland Insurance listed by HELIXon the group's public leak site
Data size
249.32 GB
Records
796742 files

Sector and geography

This disclosure adds to ransomware activity in the Insurance sector, which has 53 disclosures indexed across all operators we track.

If your organisation is affected

A listing by HELIX means Westland Insurance appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Monitor for the data appearing on HELIX's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.