Technology

Uber Freight Investigates Data Breach After Helix Extortion Gang Claims Nearly 1 Million Files

Martin HollowayPublished 2d ago5 min readBased on 7 sources
Reading level
Uber Freight Investigates Data Breach After Helix Extortion Gang Claims Nearly 1 Million Files
Photo by Tima Miroshnichenko on Pexels

Uber Freight is investigating a "data security incident" after the Helix extortion group claimed to have exfiltrated nearly 1 million files from the logistics subsidiary and posted them to its data leak site on August 6, 2026 (Reuters). The ransomware leak-site tracker Ransomware.live recorded the claim the following day, August 7 (Ransomware.live).

An Uber Freight spokesperson told Reuters that the incident had no effect on its business operations and that its systems were running normally (Reuters). The Register confirmed on August 12 that operations remained unaffected following the breach (The Register). Uber Freight did not immediately respond to TechCrunch's questions about the incident (TechCrunch). The company has not said whether it received any correspondence from the hackers or paid a ransom.

On its data leak site, the Helix hackers claimed to have taken mailboxes, cloud storage drives, files relating to accounts payable, and dispatch documents from Uber Freight (TechCrunch). Some of the files reviewed by TechCrunch appeared to show email correspondence between Uber Freight and several of its customers, dated around mid-June, though the outlet could not immediately verify their authenticity.

Helix is not a newcomer. The group has targeted transportation companies, financial giants, and private equity firms throughout 2026 in a spate of attacks in recent weeks (TechCrunch). Its methodology is consistent: exfiltrate large volumes of data from victims' cloud environments and threaten to publish it unless a ransom is paid. Google's threat intelligence team tracks the group under the umbrella designation UNC6671 and has documented its operational tradecraft in detail (Google Cloud blog).

According to Google, Helix relies heavily on social engineering, particularly voice phishing. The approach involves calling IT helpdesks and requesting password resets for targeted employees, exploiting the human layer of identity verification rather than technical vulnerabilities in cloud infrastructure (Google Cloud blog). This is a tactic that has proven effective against organizations with mature perimeter defenses but less rigorous identity-verification protocols for support calls.

The financial incentives are substantial. Google's analysis of Helix's bitcoin wallets found that the group received at least $10.6 million in ransom payments between January and May 2026 alone (TechCrunch).

The broader context here is worth attention for security teams in logistics and adjacent sectors. Helix's targeting pattern spans transportation, financial services, and private equity, which suggests the group is optimizing for organizations that hold sensitive commercial data where disclosure carries real contractual or regulatory cost. Dispatch documents and accounts payable files, the categories claimed in the Uber Freight incident, contain operational and financial details that could be leveraged in follow-on social engineering or sold to competitors.

The helpdesk vishing vector is also notable because it sits at the intersection of two persistent challenges in enterprise security: the difficulty of verifying caller identity at scale and the reliance on password resets as a routine IT function. Organizations that have invested heavily in zero-trust architecture and cloud posture management can still be undermined if an attacker can convince a helpdesk agent to reset credentials for a privileged account. Google's attribution of Helix to the UNC6671 cluster indicates that the group's tactics are well-characterized enough to build detection and prevention around, provided helpdesk procedures include strong out-of-band verification for password resets.

For Uber Freight specifically, the operational continuity claim is plausible but incomplete. An extortion attack centered on data exfiltration rather than encryption does not necessarily disrupt business operations in the way ransomware deployment would. The damage, if the exfiltration is confirmed, is to confidentiality rather than availability. But until Uber Freight confirms or denies the breach and discloses the scope of data involved, customers and partners are left to assess their own exposure based on a threat actor's claims.

The $10.6 million figure from Google's wallet analysis gives a sense of the ransom market Helix is operating in, and the success rate it implies likely explains the group's continued activity across multiple sectors. As long as the economics favor paying, the attacks will continue. The question for any organization in Helix's target profile is whether its helpdesk can withstand a phone call.