Ransomware victim disclosure
← All victimsUnknown Victim 3
Claimed by HELIX · listed 5 days ago
Status timeline
- ListedAug 13, 2026
Current state: Listed for ransom
At a glance
- Group
- HELIX
- Status
- Listed for ransom
- Listed on leak site
- Aug 13, 2026
About the victim
AI dossier — public-source company profileUnknown victim. The leak post references 'Westland' and 'Morguard' as entities that were contacted during ransom negotiation but failed to reach agreement or respond seriously.
Attack summary
Severity: medium — Confirmed exfiltration of business data (SharePoint content) with staged public release; however, no specific proof files are advertised, data volume is unstated, and no sensitive data categories (PII, financial, medical) are explicitly named. Operational context suggests corporate/real-estate entities.HELIX claims exfiltration of SharePoint libraries staged in four tiers (T1–T4). The group states it has implemented a tiered release countdown on its dark-web board, with data unlocking progressively as timers expire. Negotiation attempts by the victims were rejected or ignored by the group.
Data the group says was taken
AI dossier — extracted from the leak post- SharePoint libraries (T1–T4 tiers)
What the group claims
SharePoint libraries staged T1 (least) to T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0.
The leak post
captured from the group's sitePublished feeds. Opening a feed leaves this site for the board onion. [ Westland reached out, got the full demand, then stalled with no serious number. Contacting us and dragging process is not negotiation. ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/380506d310d5417b836512938f95a302a7fb021fbe54b9f392da079aaf9ade1e) [ Morguard reached out, took extensions, then ignored the negotiation with no real offer. Contacting us and stalling is not a strategy. Deadlines stand. Silence after outreach gets a private board and a countdown then publication. ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/c986586defd4792920f696b167ebdef91eca624746fe6cb5c6a06a0661e43d09) [ SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0. ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/p/0194658fe7e20d85cecdfb41e2e7545b5d60ac3a53314ecc52c0e239ac6e912c) [ SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0. ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7o…
Data the group says was taken
- SharePoint libraries
Screenshot of the leak post

Sources
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

