:

HELIX GROUP TARGETS SHAREPOINT WITH VISHING ATTACKS

INDUSTRY DESK2 MIN READ
THU, JUL 9, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A new data-extortion group called Helix is exploiting identity-focused tactics to infiltrate SharePoint environments and steal sensitive data. The group uses voice phishing, device code phishing, and MFA abuse to gain unauthorized access.

Who is Helix? Helix represents an emerging threat in the data-extortion landscape, focusing on identity compromise rather than traditional security vulnerabilities. The group targets organizations storing data in Microsoft SharePoint, a widely-used enterprise collaboration platform. Attack Methods Helix employs a sophisticated multi-layered approach: - Vishing (Voice Phishing): Social engineering calls to trick employees into revealing credentials or sensitive information. - Device Code Phishing: Exploiting the device authentication flow to obtain valid access tokens. - MFA Abuse: Leveraging compromised credentials to bypass multi-factor authentication protections. This combination allows attackers to establish legitimate access without triggering traditional security alerts. Operational Model As a data-extortion group, Helix likely follows the ransomware-as-a-service (RaaS) model, stealing data and threatening to publish it unless victims pay a ransom. By focusing on identity-based entry points, the group avoids detection systems designed to catch malware or network exploitation. Why SharePoint? SharePoint environments often contain centralized repositories of corporate documents, financial records, and proprietary information. Once inside, attackers can exfiltrate large volumes of data with minimal friction. Defense Recommendations Organizations should implement: - Security awareness training focused on vishing tactics - Conditional access policies requiring additional verification for sensitive data access - Monitoring for unusual device code authentication requests - Passwordless authentication where possible - Enhanced logging and detection for SharePoint access anomalies The emergence of Helix underscores a broader shift toward identity-focused attacks. As perimeter defenses strengthen, threat actors increasingly target the human and authentication layers where employees interact with systems.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Two Nigerian men have been extradited to the U.S. and charged in connection with sextortion schemes that led to the deaths of two minors in Mississippi and North Carolina.

1H AGOIndustry Desk

Threat actors are exploiting a vulnerability chain in Microsoft SharePoint to execute arbitrary code on unpatched servers. Defused has confirmed attackers are leveraging proof-of-concept exploits in the wild.

2H AGOAI Desk

Hackers have claimed to steal millions of patient records from McKesson, the major U.S. healthcare distributor. The company acknowledged the breach and warned of potential service disruptions.

2H AGOAI Desk

Artificial intelligence is becoming adept at finding and patching software vulnerabilities, potentially undermining governments' ability to deploy spyware and hacking tools. The development could spark renewed pressure for backdoors in encrypted devices.

5H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.