Uber Freight Probes Data Breach After Helix Group Claims Theft of 1 Million Files
The logistics giant is investigating a security incident after a hacking group specializing in cloud environments claimed to have stolen sensitive financial and dispatch documents.
Uber Freight is investigating a significant data security incident after a hacking group known as Helix claimed to have breached the company's network and stolen nearly 1 million files. The claim, posted to the group's data leak site on August 6, 2026, suggests a wide-scale extraction of corporate data.
According to the hackers, the stolen materials include mailboxes, OneDrive cloud storage drives, dispatch documents, and files related to accounts payable and receivable. Uber Freight has confirmed it is investigating the incident, though a company spokesperson stated the attack did not impact business operations and systems are functioning normally.
The Helix Threat Profile
The Helix group is part of a broader pattern of targeted attacks on the transportation, financial, and private equity sectors. Google has linked Helix to a larger hacker network tracked as UNC6671, which focuses on breaching cloud environments to extort ransoms from corporate victims.
UNC6671 is particularly noted for its use of sophisticated social engineering tactics. The group frequently employs voice phishing, or "vishing," to deceive IT helpdesks into resetting employee passwords. This provides attackers with legitimate credentials to bypass traditional security perimeters and gain access to internal cloud storage.
Industry Implications
This incident underscores the persistent vulnerability of critical logistics infrastructure to human-centric attacks. By targeting the IT helpdesk rather than attempting to break through hardened firewalls, groups like Helix demonstrate that the human element remains the weakest link in the corporate supply chain.
For the logistics industry, the potential exposure of dispatch and financial documents represents a significant operational risk. The theft of accounts payable and receivable data can lead to targeted fraud or the exposure of sensitive partner contracts, highlighting the high value that supply chain data holds for extortionists.
Next Steps
Uber Freight continues to probe the extent of the breach to determine exactly what data was accessed and whether any customer information was compromised. While the company maintains that operations are unaffected, the industry will be watching to see if Helix releases the stolen files or if a ransom is demanded. It remains to be seen if further evidence will emerge regarding the specific nature of the extracted mailboxes and cloud drives.