---
title: New Helix Vishing Group Emerges in SharePoint Data Theft Attacks
metaTitle: New Vishing Group Steals Data Through SharePoint
description: Helix Extortion Group Uses Vishing and MFA Abuse to Steal SharePoint Data
slug: helix-steals-data-through-sharepoint
date: "2026-07-09T12:00:00-05:00"
featured: true
image:
  src: https://cdn.securelogix.dev/slx/images/helix-1.webp
  alt: A depiction of a strand of DNA.
sourcePublisher:
  name: Bleeping Computer
  url: "https://www.bleepingcomputer.com/"
sourceArticle:
  url: "https://www.bleepingcomputer.com/news/security/new-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks/"
tags: [Vishing, MFA, Data Breach, Spoofing]
status: published
---

A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments.

Initial contact is made through vishing. In some cases, the threat actor called employees while impersonating their manager, using either the manager's name or caller ID spoofing to appear legitimate.

The purpose is to trick the target into device-code phishing schemes to gain access to their accounts.

Once inside, Helix operators quickly register a new multi-factor authenticator app for persistence, then browse and enumerate SharePoint before exfiltrating files...
