Helix — Ransomware Profile

Helix is a financially motivated extortion brand that emerged in 2026 and, per Google Threat Intelligence Group findings reported by SecurityWeek, is run by the same actors behind the BlackFile, Redact, Pink and Falcon brands, tracked as UNC6671. The cluster favors voice phishing that impersonates IT helpdesks and adversary-in-the-middle credential theft against Microsoft 365 and Okta, with TechCrunch reporting at least $10.6 million in ransoms from January to May 2026. ReliaQuest observed Helix launch a leak site that stages the release of victim data; first observed there in August 2026, it has listed at least eight US and Canadian organizations across energy, transportation, financial and professional services. Its highest-profile claim is Uber Freight, with nearly one million files claimed stolen; Uber Freight said it was investigating and that operations were unaffected.

IntelFusions coverage (1)

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions