A hacking and extortion gang says it broke into Uber Freight, the logistics arm of the ride-hailing big, and stole a trove of inner recordsdata — the newest signal that delivery and freight firms have turn into prime targets for cybercriminals. The Uber Freight information breach declare comes from a bunch often known as Helix, which posted particulars of the alleged intrusion on its darkish internet leak website earlier this week, in line with Reuters and TechCrunch.
Key takeaways
- The Helix hacking group claimed accountability for a cyberattack and information breach at Uber Freight, first reported by Reuters.
- Uber Freight says the incident had no impact on its enterprise operations and that its techniques are working usually.
- Helix claims to have taken mailboxes, cloud storage drives, accounts payable recordsdata, and dispatch paperwork.
- Google tracks Helix as a part of a broader hacking collective referred to as UNC6671, which has made at the very least $10.6 million in ransom funds between January and Might 2026.
- Uber Freight has not confirmed whether or not it obtained ransom calls for or paid the hackers.
Helix hacking group claims cyberattack on Uber Freight
Helix, a hacking and extortion outfit, took credit score for breaching Uber Freight’s techniques, marking the corporate as its latest publicized sufferer. The group posted the declare by itself information leak website, a platform it makes use of to strain victims into paying by threatening to publish stolen materials if a ransom isn’t handed over.
Uber Freight will not be an remoted goal. Helix has spent latest weeks going after transportation firms, monetary corporations, and personal fairness teams, in line with reporting reviewed by TechCrunch. The sample factors to a gang that has industrialized its strategy — choosing off sector after sector relatively than chasing one-off scores.
Nature and extent of information breach reported
Based on Helix’s personal leak-site put up, the stolen materials contains mailboxes, cloud storage drives, accounts payable recordsdata, and dispatch paperwork pulled from Uber Freight’s techniques. That blend of economic and operational data is typical of the group’s playbook: seize sufficient delicate enterprise information to make the specter of publicity credible, then use it as leverage.
TechCrunch reviewed among the recordsdata that Helix claims got here from the breach, together with what seemed to be electronic mail correspondence between Uber Freight and several other of its clients. The paperwork appeared so far again to round mid-June, although their authenticity has not been independently verified.
This element issues past the headline. If real, correspondence tied to buyer accounts may expose enterprise companions and purchasers of Uber Freight to follow-on dangers — not simply the logistics agency itself. It’s a reminder {that a} single breach inside a delivery firm’s again workplace can ripple outward to everybody that firm does enterprise with.
Uber Freight’s operational standing and response
Uber Freight informed Reuters, which first reported the incident, that the breach had no impact on its enterprise operations and that its techniques had been working usually on the time. The corporate didn’t reply to TechCrunch’s separate questions in regards to the incident.
Notably absent from Uber Freight’s public statements is any affirmation of contact with the hackers. The corporate has not stated whether or not it obtained a ransom demand from Helix, nor whether or not any cost was made. That silence is frequent within the early phases of those incidents, when firms are nonetheless assessing the scope of what was truly taken and weighing authorized and reputational concerns earlier than saying extra.
Helix group and wider UNC6671 hacking collective context
Helix isn’t working alone — it’s one piece of a bigger community. Google stated this week that it tracks Helix as a part of a broader umbrella of hackers it calls UNC6671, a designation that teams collectively a number of associated extortion operations underneath one intelligence label. That classification helps clarify why Helix’s ways and sufferer choice look constant throughout such a variety of industries: transportation, finance, and personal fairness all fall throughout the identical searching floor.
The monetary scale tied to this collective is important. Google stated a evaluation of the gang’s bitcoin wallets confirmed it had collected at the very least $10.6 million in ransom funds between January and Might 2026 alone. That determine alerts simply how worthwhile this type of extortion has turn into, and why extra teams are prone to copy the mannequin relatively than abandon it.
Social engineering and voice phishing ways
Slightly than counting on refined malware or unpatched software program flaws, Helix leans on a decidedly low-tech technique: voice phishing. The tactic includes calling an organization’s IT helpdesk immediately and posing as an worker who wants a password reset — a trick that sounds crude on paper however has repeatedly confirmed efficient in observe.
Safety researchers have lengthy flagged this type of ransomware social engineering as one of many hardest issues to defend in opposition to, exactly as a result of it targets human judgment relatively than a technical vulnerability. A helpdesk employee underneath strain to resolve a ticket shortly can turn into the weakest hyperlink in an in any other case well-defended community. That the identical strategy has now reportedly labored in opposition to a logistics arm of Uber underscores how even massive, resource-rich firms stay uncovered to assaults that don’t require any unique hacking talent in any respect.
For an trade that depends upon easy coordination between dispatchers, accounts payable groups, and clients, a breach like this raises a broader query about how nicely freight and logistics corporations have hardened their inner assist processes in opposition to precisely this sort of manipulation — particularly because the UNC6671 hacking collective continues to develop its record of targets throughout sectors.
FAQ
Who claimed accountability for the Uber Freight cyberattack?
The Helix hacking group claimed accountability for the cyberattack on Uber Freight.
Did the Uber Freight information breach have an effect on its enterprise operations?
Uber Freight reported no impact on its enterprise operations and stated its techniques had been working usually.
What info did the hackers reportedly steal from Uber Freight?
The hackers claimed to have stolen mailboxes, cloud storage drives, accounts payable recordsdata, and dispatch paperwork.
Has Uber Freight paid any ransom or communicated with the hackers?
Uber Freight has not confirmed any ransom cost or communication with the hackers.
Article produced with the help of synthetic intelligence and reviewed by the editorial crew.
