Uber Freight finds itself under scrutiny once more. A hacking group called Helix posted what it claimed were nearly one million internal files from the logistics unit on August 6. The move set off alarms across the freight industry. And the company responded by launching an investigation.
Sam Hallock, a spokesperson for Uber Freight, confirmed the probe in statements to multiple outlets. “We are investigating a data security incident involving unauthorized access to a portion of Uber Freight’s systems and repositories,” he told Reuters. The incident was identified, contained and remediated. Federal law enforcement got involved right away.
Operations continued without a hitch. “There has been no impact to Uber Freight’s business operations, which continue in the normal course without disruption,” Hallock added in comments to The Register. Systems stayed secure. Fully operational. Yet questions linger about what exactly Helix obtained. Hallock offered no comment on the authenticity of the posted data. Nor did he address when the company first learned of the claim or whether any talks occurred with the attackers.
Helix described grabbing material from mailboxes, OneDrive accounts, accounts receivable files and dispatch documents. Breach monitoring sites listed millions of rows of data. Names. Emails. Phone numbers. Even vehicle plates and street addresses appeared in some tallies. TechCrunch first highlighted the extortion gang’s claim, noting its focus on transportation firms and private equity players.
This episode hits at a sensitive time. Uber Freight, the digital brokerage arm spun from the ride-hailing giant, oversees 18 million shipments a year. Those moves carry more than $17 billion in goods. Shippers, carriers and logistics partners feed sensitive pricing, contract and routing details into its platforms daily. A leak of that scale could expose competitive bids or customer contracts. Or worse.
But the threat actors behind Helix operate as part of a larger network. Researchers at Google Threat Intelligence Group tied the brand to UNC6671, an umbrella that once ran under the BlackFile name until its retirement in May. The cluster now spreads activity across Pink, Redact, Falcon and Helix. Shared infrastructure. Overlapping phishing templates. One report from Google detailed how the actors pulled in at least $10.6 million in ransom payments between January and May through bitcoin wallets linked to the operation.
Their favorite entry point? Voice phishing. Attackers pose as IT help desk staff. They call targets on personal phones. They claim a mandatory security update or migration requires immediate action. Device code phishing follows. Credentials and authenticated sessions get handed over. Then comes the quiet exfiltration from Microsoft 365 mailboxes, cloud drives and identity systems. Okta environments have drawn their interest too.
Recent shifts in targeting show calculation. Earlier this year the group hit manufacturing, real estate, healthcare and insurance. Since June the focus moved toward technology, transportation and hospitality. Higher value sectors. Bigger payouts. Uber Freight fits the pattern perfectly. So do the private equity names already named in Google’s August 6 analysis, including Blackstone, Apollo, Bain, KKR, TPG and others.
Why the multiple brands? Google analysts offered several theories. Compartmentalization helps hide total breach volume. It isolates negotiation fallout. Internal disputes over money or operational security could have fractured the original crew. Some members might handle intrusions while others manage extortion talks. Or they simply tap the same commoditized phishing tools. The exact structure remains murky. But the results speak clearly. Victims pile up.
Freight and logistics companies sit in a tough spot. They manage sprawling partner networks. Drivers, warehouses, brokers and shippers all connect through digital platforms. Data flows constantly. Real-time tracking. Payment details. Route optimizations. One weak link, whether a contractor account or a social engineering success, can open the door wide.
Uber itself carries baggage here. The parent company endured a notorious 2022 breach tied to the Lapsus$ group. That incident exposed internal systems after social engineering snared an employee. Earlier, a 2016 attack compromised data on 57 million riders and drivers. Uber paid the hackers to delete the information and kept quiet for a year. Regulators and the public reacted harshly when details emerged. Lessons were learned. Or so the company said.
Yet the freight subsidiary now faces its own test. Class action lawyers already circle. One firm launched an investigation into potential claims for employees or others whose information may have surfaced. Sites tracking breaches added Uber Freight to their lists within days of the Helix posting. Some counted nearly five million rows. Others cited roughly one million files. Exact overlap stays unclear. Verification does too.
Security experts watching the space point to persistent challenges in cloud environments. Microsoft 365 remains a prime target across many incidents. Multi-factor fatigue, vishing bypasses and session token theft undermine traditional defenses. Organizations in transportation handle time-sensitive operations. They cannot afford prolonged outages. That pressure plays into the extortion model. Pay quickly. Or watch the data drop.
Helix has not slowed. Recent X discussions and security chatter reference its claims against other logistics and finance targets. One post noted the group’s ties to a ransomware negotiator who allegedly pocketed millions while selling out victims. Public data on those claims remains limited. But the pattern holds. Extortion first. Leak second if demands go unmet.
Uber Freight insists the matter is contained. No operational disruption. Law enforcement engaged. Still, the absence of detail on data authenticity leaves room for doubt. Did the attackers access only a sliver of repositories? Or did they roam further? Customers and partners will want answers. Insurers too. And regulators may soon knock.
The broader industry takes notice. Digital freight platforms promised efficiency and transparency. They delivered scale. Yet that same connectivity creates attractive targets. As UNC6671 and its aliases refine their vishing playbooks, more logistics operators could find themselves on leak sites. Preparation matters. Employee training against voice phishing. Strict session controls. Rapid detection in cloud logs. These steps no longer count as optional.
For now, trucks keep rolling at Uber Freight. Shipments move. The investigation proceeds behind closed doors. Helix waits on its site, files posted in stages. The files sit there for anyone to inspect. Or not. The company has not confirmed their legitimacy. But the claim alone forces attention. In an industry built on trust and data, even the suggestion of compromise carries weight.
Future updates may clarify the breach scope. Google researchers continue tracking UNC6671. Security firms monitor fresh extortion posts. And freight executives review their own defenses. The incident serves as a reminder. No operation stands immune. Especially when millions of files can vanish into the hands of a group that knows exactly how to use them.