Uber Freight Investigates Helix Data Breach Claim, Operations Normal
Uber Freight says operations remain normal after Helix claimed a cloud data breach, while stolen files, customer emails and any ransom remain unverified.
Summary
Uber Freight was reportedly investigating after hacking and extortion group Helix claimed a cyberattack and data breach, according to an August 12, 2026, TechCrunch report citing Reuters. The logistics subsidiary of Uber said operations were unaffected and systems remained normal, but did not answer TechCrunch. Helix claimed it stole mailboxes, cloud storage drives, accounts payable files and dispatch documents. TechCrunch saw apparent emails between Uber Freight and several customers dated around mid-June, but could not verify them.
Uber Freight has not disclosed whether Helix contacted it or whether any ransom was paid. Helix has attacked transportation companies, financial institutions and private equity firms throughout 2026, extracting cloud data and threatening publication. Google identifies Helix as part of UNC6671 and says it uses social engineering, including voice phishing calls that persuade IT helpdesks to reset employee passwords. Researchers call the rudimentary method highly effective. Google found that the group’s bitcoin wallets received at least $10.6 million in ransom payments from January through May 2026.
Positives
- Uber Freight said the incident had no effect on business operations and its systems were running normally.
- Uber Freight was reportedly investigating Helix’s cyberattack and data breach claims.
- Google tracks Helix within the broader UNC6671 collective and has documented its voice phishing method.
Risks & concerns
- Helix claimed it stole Uber Freight mailboxes, cloud drives, accounts payable files and dispatch documents.
- TechCrunch saw apparent mid-June customer emails among the files, although their authenticity could not be verified.
- Uber Freight has not disclosed whether Helix contacted the company or whether it paid a ransom.
- Helix has targeted transportation, finance and private equity companies by stealing cloud data and threatening to publish it.
- UNC6671-linked bitcoin wallets received at least $10.6 million in ransom payments from January through May 2026.