Uber Freight Investigating After Hacking Group Claims Data Breach

uber freight data breach helix hackers

Uber Freight, the logistics subsidiary of the ridesharing giant, is investigating a cyberattack after a hacking and extortion group calling itself Helix publicly claimed credit for breaching the company’s systems. It’s the latest in a growing string of attacks from a group that has spent much of 2026 targeting transportation, finance, and private equity firms.

What Uber Freight Has Said So Far

A spokesperson for Uber Freight told Reuters, which first reported the incident, that the breach had no effect on business operations and that the company’s systems were running normally at the time of reporting. Uber Freight did not immediately respond to TechCrunch’s follow-up questions about the incident, and the company has not confirmed whether it has received any communication from the hackers or whether a ransom demand has been made.

What the Hackers Claim to Have Stolen

On its data leak site, the platform extortion groups typically use to publish stolen files and pressure victims into paying, the Helix group claims to have taken a range of sensitive material from Uber Freight, including:

  • Email mailboxes
  • Cloud storage drives
  • Accounts payable files
  • Dispatch documents

TechCrunch reviewed some of the files posted by the group and found what appeared to be genuine email correspondence between Uber Freight and several of its customers, dated around mid-June 2026. TechCrunch noted it could not independently verify the full authenticity of the leaked material, a standard caveat in these situations since extortion groups sometimes exaggerate or fabricate portions of what they claim to have stolen to increase pressure on victims.

Who Is the Helix Hacking Group?

Uber Freight is far from Helix’s first target this year. The group has been on an active campaign throughout 2026, hitting transportation companies, financial giants, and private equity firms in a pattern of attacks. Their method typically involves breaking into a company’s cloud environment, exfiltrating large volumes of data, and then threatening to publish the stolen material publicly unless the victim pays a ransom, a classic extortion-style attack that has become increasingly common across industries.

According to Google, which tracks the group as part of a broader hacking collective it calls UNC6671, Helix relies heavily on social engineering, specifically voice phishing, where attackers call company IT helpdesks and impersonate employees to trick support staff into resetting passwords or granting account access. Despite sounding relatively low-tech compared to more sophisticated exploit-based attacks, security researchers have repeatedly warned that this kind of human-targeted manipulation remains highly effective, precisely because it exploits trust and process gaps rather than technical vulnerabilities that can be patched.

Google’s own research paints a picture of a genuinely profitable operation: a review of the group’s bitcoin wallets showed it collected at least $10.6 million in ransom payments between January and May 2026 alone.

Part of a Broader Pattern Targeting Logistics and Transportation

This incident fits into a wider trend that’s been building throughout 2026: logistics and transportation companies have become increasingly attractive targets for cybercriminal groups, not just for the sensitive customer and financial data they hold, but because compromising shipping and freight systems can also open the door to hijacking real-world goods in transit. Uber Freight’s breach follows other high-profile incidents this year involving shipping and logistics providers, underscoring how supply chain infrastructure has become a genuine cybersecurity soft spot across the industry.

What This Means for Uber Freight’s Customers

If you’re a business that works with Uber Freight for shipping or logistics services, the exposure of email correspondence and accounts payable documents raises real questions worth asking directly:

 

  • Was your correspondence among the files taken, and if so, what specific information was included?
  • Could the exposed dispatch or accounts payable data be used for follow-on fraud, such as fake invoice scams referencing real, accurate shipment details?
  • Has Uber Freight communicated directly with affected customers, or is public reporting currently the only source of information available?

Given how effective voice phishing and social engineering attacks have proven against companies with legitimate customer relationships, businesses that work with Uber Freight should treat any unexpected calls or emails referencing recent shipments or invoices with heightened scrutiny in the weeks following this disclosure.

The Bigger Trend This Fits Into

Helix’s campaign against Uber Freight is part of a broader wave of extortion-style attacks that have hit multiple industries throughout 2026, frequently using the same voice phishing playbook against IT helpdesks rather than relying on more complex technical exploits. That pattern suggests a genuine gap in how many companies, even large, sophisticated ones, train and verify identity for support staff who have the power to reset account access. As these attacks continue generating millions of dollars in ransom payments, expect the Helix group and similar operations to keep targeting logistics, finance, and private equity firms using the same fundamentally human, rather than purely technical, attack method.

For continuing coverage of data breaches, extortion campaigns, and the latest cybersecurity news affecting logistics and transportation, keep following Tech News Reports for ongoing updates.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *