Hacking Group Helix Claims Uber Freight Breach, Posts Alleged Customer Files

Social-engineering crew UNC6671 collected $10.6M in ransoms this year as Uber Freight probes cloud and mailbox exposure

Alex Barrientos Avatar
Alex Barrientos Avatar

By

Image: Uber Freight

Key Takeaways

Key Takeaways

  • Hacking group Helix stole alleged Uber Freight mailboxes, invoices, and dispatch records via voice phishing.
  • Google tracked Helix collecting over $10.6 million in ransom payments between January and May.
  • Uber Freight confirmed unauthorized access but has not disclosed ransom demands or full breach scope.

A hacking group called Helix has posted what it claims are stolen Uber Freight files — mailboxes, accounts payable records, dispatch documents, customer emails — on its leak site. Uber Freight confirmed it is investigating unauthorized access to part of its systems and repositories, and told Reuters its operations were unaffected. That’s technically reassuring. It also doesn’t answer the question freight managers are now asking about confidential files potentially now in the wrong hands.

The Group Behind the Claim

Helix isn’t a sophisticated ghost in the machine — it’s a confident caller who knows just enough to sound like your new IT vendor.

Helix, tracked by Google as UNC6671, didn’t breach Uber Freight with some zero-day exploit ripped from a spy thriller. Google says the group relies heavily on social engineering — voice phishing, specifically, aimed at corporate IT help desks. Think less Ocean’s Eleven, more a rehearsed phone call designed to make your help desk hand over the keys. Google reviewed Helix’s bitcoin wallets and found at least $10.6 million in ransom payments between January and May of this year. The group has targeted transportation companies, financial firms, and private equity — steal the cloud data, post it publicly, wait for the wire transfer. A surveillance app built to covertly target organizations offers a parallel example of how digital social-engineering operations are used against corporate targets.

Here’s what’s confirmed or alleged so far:

  • Uber Freight confirmed unauthorized access to part of its systems and repositories
  • Helix claims it obtained mailboxes, cloud storage data, accounts payable files, and dispatch documents
  • TechCrunch reviewed files appearing to show email correspondence between Uber Freight and customers, reportedly dated around mid-June
  • Authenticity of the files has not been independently verified; Uber Freight has not confirmed the scope
  • Uber Freight has not said whether it received or paid a ransom demand

“There has been no impact to Uber Freight’s business operations, which continue in the normal course without disruption,” spokesperson Sam Hallock told Reuters. “Our systems are ​secure and fully operational.”

Operational vs. Confidential

“Our systems are operational” and “customer emails aren’t on a leak site” are two entirely different statements.

The alleged file types here — invoices, dispatch records, customer correspondence — point squarely at confidential business data, not server downtime. This is extortion by publication: take the data, post enough of it to create pressure, then collect. The operational lights stay on while the sensitive material quietly surfaces elsewhere — less a blackout, more a slow leak you don’t notice until it’s already spreading. This mirrors the pattern seen in the database leak that exposed thousands of Hollywood industry records, where stolen data surfaced publicly to maximize pressure.

It’s worth noting this isn’t unfamiliar territory for Uber. A 2022 incident exposed internal tools and invoice-related data without public-facing systems going down. The pattern — operational stability alongside internal exposure — has shown up before.

Claims remain unverified. If your company routes freight through Uber Freight, “operationally fine” doesn’t confirm whether correspondence is sitting on Helix’s leak site. Watch for Uber Freight’s next disclosure — and whether the ransom question ever gets a straight answer.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →