Protect.Computer
NEWS

New Helix Group Uses Fake Phone Calls to Raid SharePoint

· 1 min read · Digital scams Got hacked
New Helix Group Uses Fake Phone Calls to Raid SharePoint

A newly discovered criminal group called Helix is running a sophisticated scam against businesses: they phone an employee directly, pretend to be that person’s manager — sometimes even spoofing the manager’s real phone number — and talk them into approving a login request on their phone. Once the employee complies, Helix has full access to the company’s Microsoft 365 account and goes straight for SharePoint to download as many files as possible. The stolen data is then used to demand a ransom, or sold to other criminals.

Helix has already hit recognizable names including Medtronic, Nissan, Kodak, and Nottingham University. Security researchers at ReliaQuest who analyzed the attacks say Helix bears a strong resemblance to previous groups like ShinyHunters and BlackFile — suggesting the same people may be behind all three. The most important thing your company can do right now is disable “device code authentication” in Microsoft 365 settings, which removes the specific login method Helix abuses most often.

How to check if you’re affected

Affected products are any Microsoft 365 or SharePoint environments where device code authentication is still enabled. If you’re an IT administrator, check your Azure Active Directory sign-in logs for unusual logins from new MFA devices or bulk SharePoint downloads. Employees should be suspicious of any unexpected phone call from a “manager” asking them to approve a login notification — that is the opening move in this attack. When in doubt, hang up and call your manager back on a number you already know.

Sources

Related reading