Quick Summary
AllegedExecutive Summary
Helix ransomware has targeted Delek US, a significant downstream petroleum operator in the United States. The company’s operations encompass oil refineries, pipelines, and retail fuel stations. SOCRadar’s Dark Web Monitoring service identified this listing on August 19, 2026. The nature of Delek US’s business, involving critical energy infrastructure and supply chains, makes it a potentially high-impact target for ransomware attacks. Disrupting operations at such a company can have far-reaching consequences, amplifying the leverage available to threat actors. Helix has demonstrated a strategic focus on energy and industrial targets, primarily within North America. Following increased regulatory scrutiny on US energy operators since the Colonial Pipeline incident in 2021, particularly concerning operational technology (OT) security, companies like Delek US remain attractive targets. Despite these regulatory pressures, mid-to-large downstream energy companies continue to be priority targets for ransomware groups due to their critical role in the energy supply chain and the potential for significant disruption.
Technical Analysis
SOCRadar’s investigation revealed that the domain severe.delekus[.]com returned 25 corporate credential records. These records were specifically linked to third-party consumer Software as a Service (SaaS) platforms. The observed pattern suggests a scenario involving a single workstation compromise, where an infected endpoint harvested credentials for all services accessed by the user. The freshness window for this data is August 19–20, 2026, indicating the compromise occurred on or just before the listing date, and the affected endpoint may still be compromised. It is important to note that the visibility into consumer SaaS platforms represents only a portion of the potential credential exposure. The same workstation that generated these logs may have also accessed enterprise systems, including VPN portals, operational technology (OT) management interfaces, and various internal applications. These enterprise credentials were not captured in the queried dataset, meaning that a broader compromise beyond consumer SaaS platforms cannot be ruled out. The proximity of the credential exposure to the ransomware listing date, and the fact that the affected endpoint may still be infected, underscores the urgency of addressing this potential access vector. Given the findings, immediate actions are recommended. These include isolating the potentially compromised endpoint, conducting a forensic examination of the full credential harvest, and auditing all enterprise systems for any authentication activity by the affected user account within the August 19–20, 2026 window. Further monitoring for continued credential exposure and reviewing authentication logs for unusual activity on enterprise systems are also crucial steps.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.