Uber Freight Investigates Data Breach After Helix Group Claims Theft of 1 Million Files
The logistics subsidiary reports that business operations remain unaffected despite claims that mailboxes and financial documents were stolen.
Uber Freight is investigating a data security incident after the Helix extortion group claimed to have breached its systems. The incident underscores the persistent risk that social engineering poses to large-scale logistics and cloud-based infrastructure.
The Helix group listed Uber Freight on its data leak site on August 6, 2026, claiming to have stolen nearly 1 million files. According to reports from SC Media and TechCrunch, the stolen data allegedly includes OneDrive accounts, mailboxes, dispatch documents, and files related to accounts receivable and payable. In response to the claim, an Uber Freight spokesperson stated that there was "no effect on its business operations and that its systems were running normally."
The Threat Actor
The Helix group is linked to the UNC6671 activity cluster, a sophisticated threat actor that also operates under the brands Pink, Redact, and Falcon. According to Google Threat Intelligence, UNC6671 specializes in targeting cloud services and identity infrastructure. The group typically avoids traditional malware in favor of social engineering tactics, specifically utilizing vishing (voice phishing) and device code phishing to gain unauthorized access to corporate environments.
Industry Implications
This breach highlights a growing trend where high-value sectors, including transportation, technology, and hospitality, are being targeted by extortion-focused groups. By focusing on identity infrastructure rather than software vulnerabilities, groups like Helix can bypass traditional perimeter defenses. For the logistics industry, the potential exposure of dispatch documents and financial records represents a significant operational risk, even if immediate system availability is maintained.
Current Status
Uber Freight has stated that the security incident was identified, contained, and remediated. While the company maintains that operations are running normally, the full extent of the data exfiltration remains under investigation. Industry observers continue to monitor the Helix leak site for the release of the claimed files, which would provide further clarity on the sensitivity of the compromised information.