Crypto Ticker:
sysadmin from Cyber Security News

Helix Data Extortion Group Uses Vishing and Device Code Phishing to Steal SharePoint Data

Tushar Subhra Dutta
Jul 9, 2026 at 07:57
25 Views
0 Comments
Helix Data Extortion Group Uses Vishing and Device Code Phishing to Steal SharePoint Data

Helix has surfaced as a fast-moving data extortion group that targets Microsoft 365 users through phone scams and cloud-focused phishing instead of traditional malware drops. Attackers are after access first, then large volumes of corporate files, with SharePoint libraries becoming a central prize in multiple incidents. The campaign stands out because it leans on identity abuse rather than noisy ransomware behavior. Victims can be talked into entering a device code, giving the threat actor a valid session that bypasses many of the warning signs defenders expect from password theft. Analysts at ReliaQuest said the activity reflects a broader shift toward identity-driven intrusion chains, and they tied Helix to a repeatable...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!