TechNewsReel
Live

Helix extortion group claims theft of 1 million files from Uber Freight

The logistics subsidiary of Uber is investigating a data security incident after a hacking collective specializing in vishing claimed a massive cloud breach.

TechNewsReel Newsroom · August 12, 2026

Uber Freight is investigating a significant data security incident after the Helix extortion group claimed to have breached the company's cloud environments on August 6, 2026. The attack underscores a growing trend of identity-focused extortion targeting critical logistics infrastructure.

The Helix group listed Uber Freight on its data leak site, alleging the exfiltration of nearly one million files. The stolen data reportedly includes mailboxes, OneDrive accounts, dispatch materials, and accounts payable and receivable documents. A spokesperson for Uber Freight confirmed the company is investigating the incident but stated that its systems were running normally and there was no effect on its business operations.

The Vishing Threat

Helix is identified by Google as part of a broader collective tracked as UNC6671. Unlike traditional ransomware groups that encrypt servers to halt operations, UNC6671 specializes in "pure extortion." The group utilizes identity-focused entry techniques, specifically "vishing"—or voice phishing—to deceive IT helpdesks into resetting employee passwords. This social engineering allows attackers to bypass multi-factor authentication (MFA) and move laterally through SharePoint and other cloud environments to steal sensitive data without triggering traditional malware alarms.

Industry Implications

This breach highlights a persistent vulnerability in large enterprises: the human element. Despite deploying advanced security stacks, companies remain susceptible to social engineering that targets the administrative processes of IT support. The financial incentive for such attacks is substantial; Google Threat Intelligence Group (GTIG) tracked over $10.6 million in Bitcoin payments to wallets associated with UNC6671 between January and May 2026 alone. By targeting a high-profile subsidiary like Uber Freight, Helix demonstrates its ability to penetrate the security perimeters of global logistics leaders.

What's Next

While Uber Freight maintains that operations remain unaffected, the company has not yet detailed the specific nature of the compromised data or whether any third-party partners were impacted. Industry observers will be watching to see if Helix releases the stolen files to pressure the company into payment, or if the investigation reveals a wider pattern of vishing attacks across the logistics sector. For now, the incident serves as a stark reminder that MFA is not a silver bullet when the authentication process itself can be manipulated via a phone call.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.