highPhishing

Helix Vishing Group - SharePoint Data Extortion Campaign

First seen Jul 10, 2026 · Updated Jul 10, 2026

vishingvoice-phishingdevice-code-phishingMFA-abuseSharePointdata-extortionidentity-attacksocial-engineeringcloud-securityagent-relevant

A newly identified data-extortion group called Helix is targeting organizations' SharePoint environments using identity-focused attack techniques, including voice phishing (vishing), device code phishing, and MFA abuse. The group's approach bypasses traditional malware-based detection by exploiting human trust and authentication weaknesses to gain access and exfiltrate sensitive data for extortion purposes.

Technical Analysis

Helix employs a multi-pronged social engineering strategy that combines vishing calls impersonating IT support with device code phishing, a technique that abuses OAuth device authorization flows to trick users into authorizing attacker-controlled sessions, granting persistent access tokens without needing the user's password. Once initial access is achieved, the group targets MFA mechanisms through prompt bombing or fatigue attacks to escalate privileges and gain full account access, then pivots into SharePoint and connected Microsoft 365 services to locate and exfiltrate sensitive documents and data. Because this attack chain relies on stolen OAuth tokens and session credentials rather than malware, it evades many endpoint detection tools and can persist even after password resets if tokens are not explicitly revoked. Organizations that use SharePoint or Microsoft 365 as a knowledge base or document store for RAG pipelines and AI agent tool integrations are at risk of having exfiltrated data include agent configuration files, API keys, or connector credentials, potentially enabling downstream compromise of connected agent systems or unauthorized data leakage from AI-accessible repositories.

Affected Systems

Microsoft SharePoint Online, Microsoft 365 tenants, Entra ID (Azure AD) authentication flows, OAuth device code authorization endpoints, MFA-enabled user accounts

Indicators of Compromise

  • No specific hashes, IPs, or domains disclosed in source reporting at time of analysis; monitor for anomalous OAuth device code authorization requests, unusual sign-in locations following vishing calls, and irregular SharePoint file access/download patterns

Remediation Steps

  1. 1

    Restrict or disable device code authentication flow

    Disable OAuth device code flow in Entra ID/Azure AD conditional access policies unless explicitly required, as this is a primary vector for token theft in this campaign.

  2. 2

    Enforce phishing-resistant MFA

    Migrate from SMS/push-based MFA to FIDO2/WebAuthn or certificate-based authentication to reduce susceptibility to MFA fatigue and social engineering attacks.

  3. 3

    Train staff against vishing and impersonation

    Conduct targeted awareness training for helpdesk and general staff on recognizing vishing tactics, especially calls impersonating IT support requesting authentication actions.

  4. 4

    Monitor and revoke suspicious OAuth tokens/sessions

    Implement continuous monitoring for anomalous token issuance and session activity in Microsoft 365; establish rapid token revocation procedures upon suspected compromise.

  5. 5

    Audit SharePoint and connected agent integrations

    Review SharePoint sites and connected services (including AI agent or RAG connectors) for exposed credentials, API keys, or sensitive data that could be leveraged if access is compromised.

Industries Most Exposed

TechnologyFinanceHealthcareProfessional ServicesGovernmentAny industry using Microsoft 365/SharePoint

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.