IT-PUB NEWS

Helix claims Uber Freight breach in extortion attack

15.08.2026 10:03 • Author: IT-PUB
Helix claims Uber Freight breach in extortion attack

Uber Freight says operations were not disrupted, while Helix claims it stole mailboxes, cloud drives, payment files and dispatch documents.

A hacking group calling itself Helix has claimed responsibility for a cyberattack and data breach at Uber Freight, Uber’s logistics arm. Uber Freight says the incident did not disrupt business operations and that its systems are still running normally. The case is drawing attention because the hackers claim they stole internal files and are threatening to publish them. It also lands amid a run of attacks tied to the same group.

The episode adds to a recent wave of breaches linked to Helix, which has targeted transportation companies, financial firms and private equity businesses. It also underscores a broader shift in extortion tactics, with attackers increasingly focused on stealing data from cloud systems rather than simply knocking services offline.

Uber Freight says business operations continued normally

Uber Freight told Reuters, which first reported the incident, that there was no effect on day-to-day business and that its systems were operating normally. The company did not immediately respond to TechCrunch’s questions about the attack.

That distinction matters. A company can keep operating after a breach, yet still face serious fallout if stolen data includes internal communications, customer records or operational documents. In this case, the hackers say they obtained mailboxes, cloud storage drives, accounts payable files and dispatch documents.

Uber Freight has not said whether it received direct contact from the hackers or whether any ransom was paid.

Helix says it took mailboxes and dispatch documents

Helix posted its claims on a data leak site, where it typically publishes stolen files to pressure victims into paying. According to the group, the material taken from Uber Freight includes mailboxes, cloud storage drives, accounts payable records and dispatch documents.

Some files viewed by TechCrunch appeared to contain email exchanges between Uber Freight and several customers. TechCrunch said it could not immediately verify whether the files were authentic. The files appeared to be dated around mid-June, as IT-PUB News notes.

If the files are genuine, the breach could matter beyond Uber Freight itself, since correspondence with customers can reveal business relationships and operational details. Even without a service outage, that kind of exposure can damage trust and complicate how companies handle logistics and payments.

Google links Helix to the UNC6671 hacking collective

Helix has been active in a string of recent hacks and is known for going after large amounts of data stored in cloud environments. The group then threatens to leak the information unless the victim pays a ransom.

Google said earlier this week that Helix belongs to a broader hacking collective it tracks as UNC6671. In the same post, Google said the group uses social engineering techniques, including voice phishing, in which attackers call IT help desks and try to convince staff to reset employee passwords.

The method is relatively simple, but security researchers have long warned that it can be effective because it targets people rather than software. Once attackers gain access through a help desk or another human channel, they can move into systems that hold sensitive business data.

Google also said a review of the gang’s bitcoin wallets showed at least $10.6 million in ransom payments between January and May this year.

The breach puts cloud theft and extortion in focus

The Uber Freight case stands at the intersection of several concerns now common in cybercrime: cloud data theft, extortion and social engineering. The issue is not just whether a company’s systems stay online. It is also what data can be taken quietly in the background and later used as leverage.

For businesses, the risk is plain enough. Even when operations continue normally, stolen files can expose internal processes, customer communications and financial documents. For users and partners, that creates uncertainty about how much information may have been exposed and whether it could be published.

The incident also fits a broader pattern in which attackers do not necessarily need especially advanced technical methods to cause harm. According to Google’s description, Helix relies heavily on convincing people to hand over access. That puts employee training, help desk procedures and password-reset checks on the cybersecurity frontline.

Uber Freight has not provided further details about the scope of the breach, the status of any negotiations or whether the stolen data has been published. For now, the company says its systems are still functioning normally, while Helix continues to claim it has sensitive material.


Improve SEO for a small/medium business website for $50