Breaking
Cyber CrimeDeveloping Story

Uber Freight breach disrupts nothing, says logistics arm

Helix extortion crew claims theft of nearly a million files from Uber Freight, but the logistics arm says operations are unaffected.

··1 hour ago·3 min read
white trailer truck on road
Photo by Robson Hatsukami Morgan on Unsplash

The logistics arm of ride-hailing giant Uber is investigating what it calls a "data security incident" after the Helix extortion group added the company to its data leak site earlier this month. Helix claims to have stolen nearly 1 million files from mailboxes, OneDrive accounts, the accounts receivable department, and other repositories. Uber Freight says the incident was contained and that business operations have continued without interruption.

Helix claims and company response

Helix listed Uber Freight on its data leak site on August 6, claiming to have exfiltrated a substantial trove of data. The extortion group, which has been linked to a cluster of recently established ransomware brands, said it obtained files from multiple sources, including email accounts, cloud storage, and financial records.

In a statement to The Register, an Uber Freight spokesperson confirmed the investigation. "We are investigating a data security incident involving unauthorized access to a portion of Uber Freight's systems and repositories. The incident was identified, contained, and remediated, and we promptly engaged federal law enforcement."

The spokesperson added, "There has been no impact to Uber Freight's business operations, which continue in the normal course without disruption. Our systems are secure and fully operational."

The Register did not download the files Helix released in stages, and Uber Freight neither confirmed nor denied that the material was authentic.

Who is Helix?

Helix is one of several recently established extortion brands that researchers have linked to infrastructure associated with BlackFile, which retired its name in May. According to Google Threat Intelligence Group (GTIG), Helix shares infrastructure with the Pink, Redact, and Falcon brands. Google tracks the wider cluster of activity as UNC6671.

The operators associated with UNC6671 often use vishing to gain an initial foothold, posing as IT helpdesk staff overseeing mandatory security migrations, Google said. They contact employees on their personal phones and use device code phishing to obtain credentials and authenticated sessions before siphoning data from cloud services such as Microsoft 365. They have also targeted Okta identity infrastructure.

Shift to high-value sectors

Researchers believe the UNC6671-linked brands have recently shifted toward organizations in higher-value sectors. Since June, they have favored technology, transportation, and hospitality targets after focusing on manufacturing, real estate, healthcare, and insurance during April and May.

The timing of the Uber Freight incident aligns with this shift, as transportation is among the sectors the group has been targeting.

Why multiple brands?

Why multiple brands emerged after BlackFile shut down is unclear. GTIG said the strategy could "compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout," although other plausible explanations exist.

Internal disagreements over matters such as handling finances and operational security could have led to the fragmentation of UNC6671, GTIG speculated. The core members may also be looking to retain control over the intrusion and data theft aspects of the attack, while outsourcing negotiations and extortion. The different groups may also just be using the same commoditized phishing tools.

A glimpse at Uber Freight's scale

Uber Freight is the ride-sharing company's logistics arm, which describes itself as "one of North America's largest managed transportation and multimodal capacity networks." Its website claims that it manages 18 million shipments carrying more than $17 billion worth of goods each year.

The company's role in moving goods across North America makes it a significant player in the supply chain, though its parent company's name recognition often overshadows its operations.

Implications for businesses

The incident underscores the persistent threat posed by extortion groups that target cloud-based identity infrastructure. Even when a company successfully contains a breach, the exposure of sensitive data can have long-term consequences, including regulatory scrutiny and reputational damage.

For other organizations, the attack highlights the importance of monitoring for vishing and device code phishing techniques, which are increasingly common in extortion attempts. The use of personal phones by employees to communicate with purported IT staff is a particularly concerning trend, as it bypasses corporate security controls.

While Uber Freight has stated that operations were not disrupted, the incident serves as a reminder that extortion groups continue to evolve their tactics, often targeting companies in critical sectors. The full scope of the data theft remains unclear, and it could take time for the company to assess the impact.

#uber-freight#helix#extortion#data-breach#unc6671

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories