Ransomware victim disclosure
← All victimsDelek US
Claimed by HELIX · listed 4 hours ago
Status timeline
- ListedAug 20, 2026
Current state: Listed for ransom
At a glance
- Group
- HELIX
- Status
- Listed for ransom
- Country
- United States
- Sector
- Oil & Gas Refining
- Listed on leak site
- Aug 20, 2026
- Data size
- 3.26 GB
- Records
- 3982 files
About the victim
AI dossier — public-source company profileDelek US is a publicly traded petroleum refining and logistics company operating in the United States. The company owns and operates refineries and distributes petroleum products.
- Industry
- Oil & Gas Refining
Attack summary
Severity: high — Confirmed exfiltration of corporate data (SharePoint libraries) from a major oil & gas refiner; staged multi-tier disclosure indicates significant data volume and sensitivity; operational scale of victim increases impact potential.HELIX claims to have exfiltrated data from Delek US, staged across four disclosure tiers on their leak site. SharePoint libraries were accessed and are being released incrementally over a timed countdown, with T1 unlocking after 12 hours and subsequent tiers following at 24-hour intervals.
Data the group says was taken
AI dossier — extracted from the leak post- SharePoint libraries
- Corporate documents
What the group claims
T1 unlocks in 12 hours, then 24 hours per remaining tier.
The leak post
captured from the group's sitePublished feeds. Opening a feed leaves this page for the board. [ Delek US is live. T1 unlocks in 12 hours, then 24 hours per remaining tier. · Operator · Board live ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/169f107db2a3ef002d03c665c3adf1f71560d1c5463ef35f720a9d5062f80d4b) [ Kennedy Jenks is live. T1–T3 are unlocked. T4 in 24 hours. · Operator · Board live ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/1ba8b0df41a617631d09ae43a2bb4a5748b5b3f2b1cd007251bb3598a5ddcf44) [ Westland reached out, got the full demand, then stalled with no serious number. Contacting us and dragging process is not negotiation. · Operator · Board live ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/380506d310d5417b836512938f95a302a7fb021fbe54b9f392da079aaf9ade1e) [ Morguard reached out, took extensions, then ignored the negotiation with no real offer. Contacting us and stalling is not a strategy. Deadlines stand. Silence after outreach gets a private board and a countdown then publication. · Operator · Board live ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/c986586defd4792920f696b167ebdef91eca624…
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

