A ransomware group calling itself Helix claims to have carried out an attack on Delek US, with the claim dated August 19, 2026. This claim comes from an entry on the group’s own leak-site listing, which is tracked by ransomware.live, a security research platform that monitors ransomware groups’ public leak sites. At this time, the claim is unverified — Delek US has not issued any public confirmation, and no regulator has confirmed that an incident occurred.
What we know — and don’t
- A group calling itself Helix listed Delek US on its leak site with a claimed date of August 19, 2026.
- Delek US operates outside the finance, legal, education, retail, and healthcare sectors as commonly classified, and is categorized here under ‘other’.
- The specific data types the group claims to have obtained have not been disclosed or confirmed by any party.
- Delek US has not issued a public statement confirming or denying the claim as of this writing.
- No regulatory filing or breach notification tied to this claim has been identified so far.
What should you do if you have an account with this company?
- Change your password for any account associated with Delek US, and avoid reusing that password on other sites.
- Enable two-factor authentication (2FA) wherever it is offered, especially for email and financial accounts.
- Be alert to phishing attempts — messages claiming to be from Delek US or related services asking you to click links or share personal information should be treated with caution.
- Monitor your financial statements and credit reports for any unfamiliar activity in the coming weeks.
- Consider using an identity monitoring service like a service like Aura or LifeLock to get alerted if your personal information appears in places it shouldn’t.
- Keep records of any suspicious communications in case they are needed later for reporting or verification purposes.
BreachLetter will update this page if Delek US confirms this incident or if it is officially reported to regulators.