Security News

Cybersecurity news aggregator

MEDIUM Attacks SC Media

New Helix data extortion group uses identity-focused tactics to target SharePoint

  • What: New group Helix targets SharePoint with identity-focused tactics
  • Impact: Risk of data exfiltration and account compromise for organizations
Read Full Article →

Identity New Helix data extortion group uses identity-focused tactics to target SharePoint July 9, 2026 Share By SC Staff (Adobe Stock) A new data-extortion group named Helix is employing identity-focused tactics, including voice phishing (vishing), device code phishing, and multi-factor authentication abuse, to steal data from SharePoint environments, Bleeping Computer reports. Helix initiates contact through vishing, sometimes impersonating managers via caller ID spoofing, to trick targets into device-code phishing schemes for account access, according to a report by ReliaQuest. Once inside, attackers register new MFA apps for persistence, then enumerate and exfiltrate files from SharePoint. Researchers at ReliaQuest believe Helix may have links to the ShinyHunters and BlackFile data extortion groups due to shared techniques and infrastructure, such as the use of the NICENIC registrar and similar social engineering playbooks. The exfiltration of SharePoint data is considered Helix's strongest technical fingerprint. ReliaQuest recommends disabling device code authentication where possible, restricting SharePoint access to managed devices, and blocking newly registered domains to defend against these attacks. Source: Bleeping Computer SC Staff Related Identity Permiso launches risk score engine for unified identity security SC Staff July 9, 2026 The Risk Score Engine generates three key outputs: Identity Risk Scores to rank the riskiest identities, Session Scores to flag immediate investigation needs, and Organization Risk Scores to provide a single, benchmarkable tenant-level metric. Identity Hong Kong SFC mandates stronger login security for crypto platforms SC Staff July 9, 2026 The SFC has mandated that all virtual asset trading platforms and internet brokers must replace one-time password (OTP) logins, including those sent via SMS and email, with phishing-resistant authentication methods within 12 months. Identity The Intercept warns of compromised Signal tipline username SC Staff July 9, 2026 An analysis by Dr. Martin Shelton of the Freedom of the Press Foundation suggests several ways the Signal username could have been compromised. Related Events Cybercast The identity evolution that enables AI confidence Tue Aug 11 Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) You can skip this ad in 5 seconds

Share this article