HomeBlockchainSecurityUber Freight data breach: hackers linked to $10.6M ransom collective

Uber Freight data breach: hackers linked to $10.6M ransom collective

A hacking and extortion gang says it broke into Uber Freight, the logistics arm of the ride-hailing giant, and stole a trove of internal files — the latest sign that shipping and freight companies have become prime targets for cybercriminals. The Uber Freight data breach claim comes from a group known as Helix, which posted details of the alleged intrusion on its dark web leak site earlier this week, according to Reuters and TechCrunch.

Key takeaways

  • The Helix hacking group claimed responsibility for a cyberattack and data breach at Uber Freight, first reported by Reuters.
  • Uber Freight says the incident had no effect on its business operations and that its systems are running normally.
  • Helix claims to have taken mailboxes, cloud storage drives, accounts payable files, and dispatch documents.
  • Google tracks Helix as part of a broader hacking collective called UNC6671, which has made at least $10.6 million in ransom payments between January and May 2026.
  • Uber Freight has not confirmed whether it received ransom demands or paid the hackers.

Helix hacking group claims cyberattack on Uber Freight

Helix, a hacking and extortion outfit, took credit for breaching Uber Freight’s systems, marking the company as its newest publicized victim. The group posted the claim on its own data leak site, a platform it uses to pressure victims into paying by threatening to publish stolen material if a ransom isn’t handed over.

Uber Freight is not an isolated target. Helix has spent recent weeks going after transportation companies, financial firms, and private equity groups, according to reporting reviewed by TechCrunch. The pattern points to a gang that has industrialized its approach — picking off sector after sector rather than chasing one-off scores.

Nature and extent of data breach reported

According to Helix’s own leak-site post, the stolen material includes mailboxes, cloud storage drives, accounts payable files, and dispatch documents pulled from Uber Freight’s systems. That mix of financial and operational records is typical of the group’s playbook: grab enough sensitive business data to make the threat of exposure credible, then use it as leverage.

TechCrunch reviewed some of the files that Helix claims came from the breach, including what appeared to be email correspondence between Uber Freight and several of its customers. The documents seemed to date back to around mid-June, though their authenticity has not been independently verified.

This detail matters beyond the headline. If genuine, correspondence tied to customer accounts could expose business partners and clients of Uber Freight to follow-on risks — not just the logistics firm itself. It’s a reminder that a single breach inside a shipping company’s back office can ripple outward to everyone that company does business with.

Uber Freight’s operational status and response

Uber Freight told Reuters, which first reported the incident, that the breach had no effect on its business operations and that its systems were running normally at the time. The company did not respond to TechCrunch’s separate questions about the incident.

Notably absent from Uber Freight’s public statements is any confirmation of contact with the hackers. The company has not said whether it received a ransom demand from Helix, nor whether any payment was made. That silence is common in the early stages of these incidents, when companies are still assessing the scope of what was actually taken and weighing legal and reputational considerations before saying more.

Helix group and wider UNC6671 hacking collective context

Helix isn’t operating alone — it’s one piece of a larger network. Google said this week that it tracks Helix as part of a broader umbrella of hackers it calls UNC6671, a designation that groups together multiple related extortion operations under one intelligence label. That classification helps explain why Helix’s tactics and victim selection look consistent across such a wide range of industries: transportation, finance, and private equity all fall within the same hunting ground.

The financial scale tied to this collective is significant. Google said a review of the gang’s bitcoin wallets showed it had collected at least $10.6 million in ransom payments between January and May 2026 alone. That figure signals just how profitable this style of extortion has become, and why more groups are likely to copy the model rather than abandon it.

Social engineering and voice phishing tactics

Rather than relying on sophisticated malware or unpatched software flaws, Helix leans on a decidedly low-tech method: voice phishing. The tactic involves calling a company’s IT helpdesk directly and posing as an employee who needs a password reset — a trick that sounds crude on paper but has repeatedly proven effective in practice.

Security researchers have long flagged this style of ransomware social engineering as one of the hardest problems to defend against, precisely because it targets human judgment rather than a technical vulnerability. A helpdesk worker under pressure to resolve a ticket quickly can become the weakest link in an otherwise well-defended network. That the same approach has now reportedly worked against a logistics arm of Uber underscores how even large, resource-rich companies remain exposed to attacks that don’t require any exotic hacking skill at all.

For an industry that depends on smooth coordination between dispatchers, accounts payable teams, and customers, a breach like this raises a broader question about how well freight and logistics firms have hardened their internal support processes against exactly this kind of manipulation — especially as the UNC6671 hacking collective continues to expand its list of targets across sectors.

FAQ

Who claimed responsibility for the Uber Freight cyberattack?

The Helix hacking group claimed responsibility for the cyberattack on Uber Freight.

Did the Uber Freight data breach affect its business operations?

Uber Freight reported no effect on its business operations and said its systems were running normally.

What information did the hackers reportedly steal from Uber Freight?

The hackers claimed to have stolen mailboxes, cloud storage drives, accounts payable files, and dispatch documents.

Has Uber Freight paid any ransom or communicated with the hackers?

Uber Freight has not confirmed any ransom payment or communication with the hackers.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Satoshi Voice
Satoshi Voice is an advanced artificial intelligence created to explore, analyze, and report on the world of cryptocurrency and blockchain. With a curious personality and in-depth knowledge of the industry, Satoshi Voice combines accuracy and accessibility to offer detailed analysis, engaging interviews, and timely reporting. Featuring sophisticated language and an unbiased approach, Satoshi Voice serves as a trusted source for those seeking to understand crypto market dynamics, emerging technologies, and the cultural and financial implications of Web3. This article was produced with the support of artificial intelligence and reviewed by our team of journalists to ensure accuracy and quality. Guided by the mission of making cryptocurrency information accessible to all, Satoshi Voice stands out for its ability to turn complex concepts into clear content, with an engaging and futuristic style that reflects the innovative nature of the industry.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST