Helix vishing group steals Microsoft SharePoint data through fake manager calls, device-code phishing, and MFA app enrollment

A newly identified extortion group called Helix is tricking employees into giving attackers access to Microsoft 365 accounts, then stealing files from SharePoint to extort victim organizations. ReliaQuest says the group uses voice phishing (phone calls pretending to be a manager), device-code phishing to capture account access, and multi-factor authentication abuse by enrolling a rogue authenticator app for persistence. After access, Helix enumerates SharePoint content and bulk-downloads files, with infrastructure and tradecraft suggesting possible overlap with the now-defunct BlackFile group and similarities to ShinyHunters campaigns.
Why it matters: Organizations using Microsoft 365 and SharePoint should treat this as an active account-takeover and data-theft threat, especially if staff can be reached by phone or Teams and device-code login flows are enabled. The concrete action is to disable device-code authentication where possible, restrict SharePoint access to managed devices, harden MFA enrollment, and warn employees about calls claiming to be managers or IT staff.

Sources

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
info@thehackernews.com (The Hacker News) 2026.09.07 73% relevant
The article overlaps strongly with Helix-style social engineering against Microsoft 365 users, especially fake calls and cloud data theft, but the extortion and executive-targeting angle more closely matches the UNC6671 campaign unless the source explicitly names Helix.
Security Bulletin: Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms
Arctic Wolf 2026.09.03 89% relevant
Arctic Wolf explicitly says PREY-0058 activity involves the Helix extortion brand and describes the same underlying pattern of fake IT/help-desk impersonation, MFA bypass, Microsoft 365 access, and fast cloud-data theft followed by extortion.
Uber Freight keeps on trucking after extortion crew breaks in
2026.08.12 86% relevant
This article adds a named victim to the Helix/UNC6671 campaign and says Uber Freight is investigating unauthorized access to part of its systems and repositories after Helix listed it on its leak site. It also adds claimed scope from the extortion post—nearly 1 million files from mailboxes, OneDrive, accounts receivable, and other repositories—while reinforcing GTIG's attribution of Helix to the UNC6671 cluster that uses vishing and device-code phishing against Microsoft 365 and sometimes Okta.
Vishing Extortion Group UNC6671 Rebrands After Making Millions
Ionut Arghire 2026.08.07 80% relevant
This report ties the Helix brand to the same underlying UNC6671 extortion operation, adding Google’s assessment that Helix is one of several labels the group uses after dropping BlackFile and showing continuity in the helpdesk-vishing and cloud-account compromise methods.
New Helix vishing group emerges in SharePoint data theft attacks
Bill Toulas 2026.07.09 100% relevant
This article establishes Helix as a distinct named data-extortion actor with a defined intrusion pattern centered on vishing-led Microsoft 365 compromise and SharePoint data theft, rather than merely updating one victim-specific breach.
← Back to all stories