ZeroHour

helix

ransomware group · aka BlackFile (name used in recent reporting on the group's attacks on financial companies) · unknown · active since 2026-08-06 (first listed post on the leak site tracked by this dashboard); broader activity history unknown

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
5
All-time (tracked)
5since 2026-08-06
Last post
08-06 23:26UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Helix is a low-volume data-extortion group whose listing on the leak site tracked by this dashboard dates to its first post on 2026-08-06, with five victims posted since and none in the past 30 days. Its victims span logistics, technology, real estate, and insurance, suggesting opportunistic rather than sector-specific targeting. Recent reporting discusses the group's attacks on financial companies under the BlackFile name and describes a human-operated social-engineering approach rather than exploit-based intrusion. Reported techniques include vishing calls impersonating IT support, fake Microsoft 365 passkey alerts used to hijack accounts, and targeting employees' personal phones to steal SaaS data, with coverage linking this vishing activity to the cluster tracked as UNC6671. No public earnings estimates and no specific CVEs are associated with the group in reviewed reporting.

Tactics & tooling
  • Vishing (voice phishing) calls impersonating IT support personnel (per recent vendor reporting)
  • Fake Microsoft 365 passkey-enrollment alerts used to hijack user accounts
  • Targeting of employees' personal phones to obtain SaaS credentials and data; coverage links this to vishing tracked as UNC6671
  • Human-operated social engineering prioritized over software exploitation; no specific CVEs cited in reviewed reporting
  • Publication of victim names on a dedicated leak/extortion site (low posting volume)
Targeted sectors
Logistics and transportationTechnologyReal estateInsuranceFinancial services (reported focus in recent coverage)
Notable public victims

Uber, Venture Logistics, Highwoods Properties, Morguard, Westland Insurance

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Venture Logistics · Aug 6, 2026SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0.
Uber · Aug 6, 2026SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0.
Highwoods Properties · Aug 6, 2026SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0.
Morguard · Aug 6, 2026Morguard reached out, took extensions, then ignored the negotiation with no real offer. Contacting us and stalling is not a strategy. Deadlines stand. Silence after outreach gets a private board and a countdown then publication.
Westland Insurance · Aug 6, 2026Westland reached out, got the full demand, then stalled with no serious number. Contacting us and dragging process is not negotiation.

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .