> Back to All Posts

New Helix Vishing Attacks Target SharePoint Data

Helix Vishing Attacks

A cybercrime group calling itself Helix has started targeting corporate SharePoint environments using a mix of phone calls, stolen credentials, and multi-factor authentication abuse. Rather than deploying malware, Helix vishing attacks rely on tricking employees into handing over account access directly. The result is the same as any major breach: sensitive files exposed, and companies facing extortion demands to keep that data from going public.

How Helix Vishing Attacks Begin

Every Helix operation starts with a phone call. Operators contact employees directly, and in several cases they pose as the target’s own manager. They pull this off either by using the manager’s real name or by spoofing the caller ID to make the call look internal. This approach works because it exploits trust rather than a technical flaw.

Once an employee is on the line, the attacker steers them toward device code phishing. This technique tricks the victim into approving a login request on the attacker’s behalf, effectively handing over the keys to their Microsoft 365 account without ever stealing a password. Because the process rides on legitimate authentication flows, it can slip past defenses that only watch for suspicious logins or unfamiliar devices.

From Phone Call to Full Account Access

After gaining entry, Helix operators move fast to lock in their access. They register a new multi-factor authentication app on the compromised account, which lets them stay logged in even if the employee later changes their password. This step turns a single successful phone call into long-term access.

From there, the group pivots straight to SharePoint. Helix vishing attacks consistently follow the same script at this stage: broad searches across site content, followed by bulk downloads of whatever files the account can reach. Security researchers at ReliaQuest identified specific search patterns, including wildcard queries and site-content filters, tied to a single IP address and a consistent automated tool. That repeated pattern gives defenders one of the clearest signals for spotting Helix activity before data leaves the network.

Inside a SharePoint Data Heist

Once the exfiltration finishes, the group’s goals become financial rather than technical. Stolen files get used as leverage, with victims told to pay up or see their data published. In other cases, Helix sells the material to other cybercriminals instead of running the extortion itself.

This pattern mirrors how several other extortion groups now operate. Instead of encrypting systems with ransomware, they extract data quietly and threaten exposure. Because nothing gets locked down, victims often do not realize the breach happened until the attackers make contact.

Ties to ShinyHunters and BlackFile

Researchers believe Helix did not appear out of nowhere. Its social engineering playbook closely resembles ShinyHunters, a group that has claimed breaches at organizations including Medtronic, Nissan, Kodak, and Nottingham University over the past month. Both groups favor vishing, manager impersonation, and SharePoint targeting through Microsoft 365 accounts.

A second thread connects Helix to BlackFile, a now-defunct group that used similar identity-based tactics before shutting down in April. One Helix attack used an exfiltration IP address in the same autonomous system as a confirmed BlackFile address, pointing to shared infrastructure between the two. Helix also emerged shortly after BlackFile went dark, which researchers say could indicate a direct continuation of that earlier operation under a new name.

Neither connection has been confirmed outright, but the overlap in domain registrars, infrastructure, and attack methods makes coincidence unlikely. Analysts have flagged other groups, including Pink and Redact, as possible offshoots from the same collapsed operation.

How to Defend Against Helix Vishing Attacks

Because Helix relies on identity abuse rather than malware, standard antivirus tools offer little protection. The most effective defense is disabling device code authentication wherever it is not strictly needed, since that single setting closes off the exact method Helix uses to hijack accounts.

Organizations can also reduce their exposure with a few additional steps. Restricting SharePoint access to managed, company-owned devices limits what an attacker can reach even after a successful vishing call. Blocking traffic to newly registered domains helps too, since Helix and similar groups often stand up fresh infrastructure right before an attack. Employee training still matters here. Staff who know to verify unexpected calls from “managers,” especially ones requesting login approval, remove the weak link Helix depends on most.

Final Thoughts

Helix shows how far identity-based attacks have evolved beyond simple phishing emails. A convincing phone call, a spoofed caller ID, and one approved login request are all it takes to open the door to a company’s entire SharePoint library. As more extortion groups adopt this playbook, the defense has to shift too, away from just blocking malware and toward verifying who is actually asking for access in the first place.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.