Technology

Hackers Claim They Stole Nearly 1 Million Files From Uber Freight. What Happened?

Martin HollowayPublished 2d ago4 min readBased on 7 sources
Reading level
Hackers Claim They Stole Nearly 1 Million Files From Uber Freight. What Happened?
Photo by Tima Miroshnichenko on Pexels

Uber Freight is investigating a "data security incident" after a group of hackers called Helix claimed to have stolen nearly 1 million files from the logistics company and posted them online on August 6, 2026 (Reuters). A website that tracks hacker claims, Ransomware.live, recorded the claim the following day, August 7 (Ransomware.live).

An Uber Freight spokesperson told Reuters that the incident had no effect on its business operations and that its systems were running normally (Reuters). The Register confirmed on August 12 that operations remained unaffected following the breach (The Register). Uber Freight did not immediately respond to TechCrunch's questions about the incident (TechCrunch). The company has not said whether it received any correspondence from the hackers or paid a ransom.

On its website, the Helix hackers claimed to have taken email inboxes, cloud storage drives, files relating to accounts payable, and dispatch documents from Uber Freight (TechCrunch). Some of the files reviewed by TechCrunch appeared to show email correspondence between Uber Freight and several of its customers, dated around mid-June, though the outlet could not immediately verify their authenticity.

Helix is not a newcomer. The group has targeted transportation companies, financial giants, and private equity firms throughout 2026 in a spate of attacks in recent weeks (TechCrunch). Its approach is consistent: steal large volumes of data from victims' online systems and threaten to publish it unless a ransom is paid. Google's threat intelligence team tracks the group under the designation UNC6671 and has documented its methods in detail (Google Cloud blog).

According to Google, Helix relies heavily on social engineering, particularly voice phishing. The approach involves calling a company's IT helpdesk and pretending to be an employee who needs a password reset. The attacker is exploiting the human being on the other end of the phone rather than breaking through technical security barriers (Google Cloud blog). The tactic has proven effective against organizations with strong technical defenses but weaker procedures for confirming who is actually on the call.

The financial incentives are substantial. Google's analysis of Helix's bitcoin wallets found that the group received at least $10.6 million in ransom payments between January and May 2026 alone (TechCrunch).

The broader context here is worth attention. Helix's targeting pattern spans transportation, financial services, and private equity, which suggests the group is choosing organizations that hold sensitive commercial data where disclosure carries real contractual or regulatory cost. Dispatch documents and accounts payable files, the categories claimed in the Uber Freight incident, contain operational and financial details that could be used in follow-on scams or sold to competitors.

The helpdesk phone scam is also notable because it sits at the intersection of two persistent challenges in corporate security: the difficulty of confirming who is really calling and the routine practice of resetting passwords when employees ask. Organizations that have invested heavily in advanced security architecture can still be undermined if an attacker can convince a helpdesk agent to reset the password for an important account. Google's detailed tracking of Helix under the UNC6671 label indicates that the group's methods are well understood enough to build defenses around, provided helpdesk procedures include strong secondary verification for password resets.

For Uber Freight specifically, the claim that operations are running normally is plausible but incomplete. An attack focused on stealing data rather than locking systems down does not necessarily disrupt day-to-day business in the way that ransomware, which encrypts files and demands payment to unlock them, would. The damage, if the theft is confirmed, is to confidentiality rather than to whether the systems keep running. But until Uber Freight confirms or denies the breach and discloses what data was involved, customers and partners are left to assess their own risk based on a hacker's claims.

The $10.6 million figure from Google's wallet analysis gives a sense of the ransom market Helix is operating in, and the success rate it implies likely explains the group's continued activity across multiple sectors. As long as the economics favor paying, the attacks will continue. The question for any organization in Helix's target profile is whether its helpdesk can withstand a phone call.