Data breach
Delek US
- Records
- 122,079
- Breach date
- 19 August 2026Estimated
- Added
- 27 August 2026
What was exposed
10 types of data · 3 put you at serious risk
- Names122,079
- Street addresses53,566
- Phone numbers47,501
- Email addresses44,264
- Licence plates9,359
- Dates of birth9,321
- Vehicle VINs4,536
- Social security numbers1,257
- Driving licence numbers1,072
- Bank account numbers88
About this breach
Delek US, a publicly traded petroleum refining and logistics company, appears in a ransomware extortion listing by a group calling itself Helix. According to our investigation team, the breach is estimated to have occurred on August 19, 2026, and the indexed records total 122,079 rows. Helix claimed responsibility in a post tracked by Ransomware.live and summarized by iThome, stating it had stolen data from the company's SharePoint libraries and threatened to publish it in stages if its demands were not met. Delek US, which operates refineries in Texas, Arkansas, and Louisiana, had not publicly confirmed the incident in sources reviewed.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
August 19, 2026: Helix posted a claim on its leak site saying it had stolen SharePoint data from Delek US, with plans to release material in tiers on a countdown schedule, according to Ransomware.live data reported by iThome.
August 20, 2026: Threat-intelligence tracking site Darkfield recorded Delek US as listed for ransom on the Helix leak board, with the group describing 3.26 GB of data across thousands of files.
What Information Was Compromised?
Our analysis found the following data types in this breach: 122,079 names, 53,566 street addresses, 47,501 phone numbers, 44,264 email addresses, 9,359 vehicle license plates, 9,321 dates of birth, 4,536 vehicle VINs, 1,257 Social Security numbers, 1,072 driver's licenses, and 88 bank account records.
Not every individual is affected by every type of data listed here.
Because the records include core identity details alongside vehicle and financial information, the exposure is unusually specific. The presence of Social Security numbers and bank account entries, even in small counts, raises the stakes beyond a typical contact-list leak.
What Are the Potential Risks for Affected Individuals?
Social Security numbers combined with names, birth dates, and addresses are the raw material for identity theft, including fraudulent loan and credit applications. Bank account details can enable direct payment fraud. Phone numbers and email addresses invite targeted phishing, and the vehicle plate and VIN data makes convincing car-related scams easier, such as fake registration or recall notices. Scammers may reference real details from the leak to appear legitimate, so treat unexpected calls, texts, or emails about your finances or vehicle with suspicion.
What Is Delek US Doing in Response?
Delek US has not published a breach notification or issued a public statement confirming the incident as of September 25, 2026, in sources reviewed. A ClassAction.org page notes that lawyers are evaluating the hackers' claims, but no lawsuit details or company statements were available at that time. Without an official notice, it is not possible to confirm how many people the company believes were affected or what remediation is underway.
What Should You Do If You Were Affected?
Place a fraud alert or a security freeze on your credit files with Equifax, Experian, and TransUnion. A freeze is free and blocks most new credit from being opened in your name.
Review your bank and credit card statements regularly for charges you did not make, and report anything unfamiliar to your bank immediately.
Watch for phishing emails or texts that reference Delek US, your vehicle, or your accounts. Do not click links or share verification codes with unsolicited contacts.
If your driver's license or plate numbers were exposed, be alert to fake DMV or toll notices, and consider renewing license numbers if your state allows it after fraud.
File a report at IdentityTheft.gov if you see signs of identity theft, and keep records of any fraudulent activity for disputes.
In the news
- iThome security daily report, August 24, 2026ithome.com.tw (opens in a new tab)
- ClassAction.org, Delek US data breach lawsuits pageclassaction.org (opens in a new tab)
- Darkfield, Delek US HELIX ransomware listingdarkfield.orizon.one (opens in a new tab)
- Ransomware.liveransomware.live (opens in a new tab)
