DMR News

Advancing Digital Conversations

Uber Freight Investigates Data Breach Claimed by Helix Extortion Group

ByJolyen

Aug 13, 2026

Uber Freight Investigates Data Breach Claimed by Helix Extortion Group

Uber Freight is investigating a cybersecurity incident after the Helix extortion group claimed it stole data from the logistics company’s systems. Uber Freight said unauthorized access affected part of its systems and repositories, but its business operations were not disrupted and its systems remain operational.

Helix claimed on its data leak site that it obtained mailboxes, cloud storage drives, accounts payable files, and dispatch documents belonging to Uber Freight. Some files reviewed by TechCrunch appeared to contain correspondence between Uber Freight and customers from around mid-June, although their authenticity has not been independently verified.

Uber Freight has not disclosed how much information was accessed or whether it has received a ransom demand. The company also has not said whether it has communicated with the attackers or made any payment.

Helix Linked to Wider Extortion Campaign

Google Threat Intelligence Group tracks Helix as one of several extortion brands connected to a hacking cluster known as UNC6671. In its official analysis, Google said the same infrastructure and tactics have been associated with brands including Redact, Pink, Helix, and Falcon.

UNC6671 has targeted dozens of organizations across North America, Australia, and the UK since emerging in early 2026. The group primarily uses voice phishing and credential-harvesting websites rather than exploiting technical vulnerabilities in the affected cloud services.

Attackers may impersonate IT or helpdesk personnel and persuade employees to enter login credentials and multi-factor authentication codes into fraudulent websites. Once an account is compromised, the group has used single sign-on access to reach services such as Microsoft 365, SharePoint, OneDrive, Salesforce, and Zendesk.

Google said its analysis of cryptocurrency wallets linked to the operation identified at least $10.6 million in ransom payments between January and May 2026.

Uber Freight Says Operations Continue Normally

Uber Freight spokesperson Sam Hallock told Reuters that the incident involved unauthorized access to a portion of the company’s systems and repositories. He said there had been no effect on business operations and that the company’s systems were secure and fully operational.

Uber Freight has not published a dedicated public announcement about the incident on its own website as of August 13. Its parent company, Uber Technologies, has previously described cybersecurity incident management as part of its security program, including investigating threats, mitigating their impact, and implementing measures intended to prevent recurrence.

The Uber Freight incident follows other recent attacks attributed to the same wider extortion operation, which has targeted companies in transportation, financial services, and private equity. Google said the campaign demonstrates how social engineering can provide attackers with access to sensitive enterprise cloud environments without exploiting weaknesses in the cloud providers themselves.


Featured image credits: Magnific.com

For more stories like it, click the +Follow button at the top of this page to follow us.

Jolyen

As a news editor, I bring stories to life through clear, impactful, and authentic writing. I believe every brand has something worth sharing. My job is to make sure it’s heard. With an eye for detail and a heart for storytelling, I shape messages that truly connect.

Leave a Reply

Your email address will not be published. Required fields are marked *