Uber Freight Investigates Cyber Incident After Hackers Claim Data Theft
Key Takeaways
- Uber Freight Is Investigating a Cyber Incident: The logistics company is investigating after the Helix hacking and extortion group claimed it stole data from its systems, while Uber Freight says business operations remain unaffected.
- Hackers Claim They Stole Business and Customer Data: Helix says it obtained mailboxes, cloud-storage drives, accounts-payable files and dispatch documents. TechCrunch reviewed files that appeared to contain customer correspondence but could not independently verify their authenticity.
- The Attack Highlights a Different Kind of Operational Risk: A company can remain fully operational while attackers quietly remove sensitive information, shifting the immediate concern from business interruption to data exposure and extortion.
- Social Engineering Remains a Critical Weakness: Google has linked Helix to the broader UNC6671 cluster, whose attackers have used tactics including voice phishing to persuade employees and IT help desks to provide access to corporate systems.
- The Incident Carries Potential Third-Party Consequences: Because logistics providers hold information flowing among shippers, carriers and customers, a breach can expose organizations that were never directly compromised themselves.
Deep Dive
Uber Freight says its logistics business is investigating a cybersecurity incident after the hacking and extortion group Helix claimed it had stolen data from the company, according to Reuters, which first reported the incident. An Uber Freight spokesperson told Reuters there had been no impact on business operations and that its systems were operating normally.
Helix tells a different part of the story. On the data-leak site where the group publishes material allegedly taken from its victims, the hackers claimed to have obtained mailboxes, cloud-storage drives, accounts-payable files and dispatch documents from Uber Freight. TechCrunch reviewed some of the files and said they appeared to include email correspondence between Uber Freight and several customers, with material dated around mid-June. The publication could not independently verify that the files were authentic.
Uber Freight has not said whether Helix contacted the company, whether a ransom was demanded or whether any payment was made. Nor has the company publicly established the extent of any data that may have been taken.
Those unanswered questions matter because an intrusion does not have to stop a business to become a serious business problem. The older image of a cyberattack is conspicuous: screens go dark, files become inaccessible, employees are locked out and operations grind down while a ransom demand waits somewhere on the network. Extortion groups have learned that destruction is not always necessary. Sometimes the more valuable thing is to get in quietly, copy what is useful and leave the machinery running.
Helix has made that model its business. The group has targeted transportation companies, financial firms and private-equity businesses during a recent series of attacks, seeking access to corporate cloud environments and removing large amounts of data that can later be used as leverage. The threat comes afterward: pay, or the information may be published.
Google has identified Helix as part of a broader collection of hackers it tracks as UNC6671. The techniques attributed to the group are striking less for their sophistication than for their familiarity. Attackers have relied on social engineering, including voice phishing, in which someone calls an employee or IT help desk and persuades the person on the other end to reset a password or otherwise help provide access.
There is something almost stubbornly ordinary about the method. Companies can spend heavily on security architecture and still find themselves defending a moment in which one person sounds convincing enough on the telephone.
Once that moment succeeds, the cloud can do exactly what it was built to do: make information easy to reach. Email accounts, shared drives and business applications concentrate years of correspondence and operational records behind credentials intended to give legitimate employees convenient access. An attacker who manages to assume that identity can inherit the convenience along with it.
For a logistics company, the implications can extend beyond its own walls. Freight businesses occupy a crowded middle ground between shippers, carriers and customers, and the records necessary to coordinate that work can contain information belonging to companies that never suffered an intrusion themselves. The alleged presence of customer correspondence among the Uber Freight files, if ultimately verified, is a reminder of how quickly a cybersecurity incident can become a third-party risk event.
Recent attacks elsewhere in the transportation sector have shown the same problem. A compromise at a logistics provider can travel outward through the commercial relationships represented in its systems, leaving customers to determine whether their own information was among the material exposed.
The economics help explain why attackers keep trying. Google said a review of bitcoin wallets connected with the Helix operation showed at least $10.6 million in ransom payments between January and May of this year. The methods may be rudimentary, but the returns apparently have not been.
That leaves Uber Freight with an investigation whose most important findings may have little to do with whether its systems stayed online. The company has already said that operations were unaffected. It must now determine the reach of the intrusion: what the attackers accessed, what they removed, whether the material posted by Helix is genuine and whether customers or other parties are caught inside it.
Operational recovery has traditionally offered companies a recognizable finish line after a cyberattack. Stolen data does not. Once information has been copied outside the environment that was supposed to contain it, there is no restoration process that puts the original boundary back where it was. The systems may keep running. The consequences can arrive later.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

