📡 Breaking news
Analyzing latest trends...
AI Text-to-Speech.

Uber Freight Probes Data Breach as Hacker Group Helix Claims Theft of 1M Files.

Uber Freight Probes Data Breach as Hacker Group Helix Claims Theft of 1M Files.
Uber Freight Investigates Major Breach as Hacker Group 'Helix' Claims Leak of 1 Million Files

Uber Technologies Inc. freight division is actively investigating a data security breach after a cybercriminal group known as "Helix" posted data on its dark web leak site, claiming to have stolen nearly 1 million files from the logistics firm.

Uber spokesperson Sam Hallock confirmed that the company identified and contained the unauthorized access, reassuring customers that core logistics operations remain unaffected and fully functional. The incident highlights an escalating wave of cyber extortion campaigns targeting critical U.S. logistics, financial, and enterprise infrastructure.

The Helix Group & The UNC6671 Connection

On August 6, Helix uploaded what it alleged were internal Uber Freight records. While Uber verified that unauthorized access to certain internal cloud data repositories took place, the company has not authenticated the contents of the leaked files.

Threat research published by Google Threat Intelligence Group (GTIG) links Helix to a broader, highly active cyber-extortion cluster tracked as UNC6671. Formerly associated with the BlackFile extortion brand, UNC6671 has recently operated under multiple rebrands including Helix, Redact, Pink, and Falcon using shared attack infrastructure.

A Systematic Campaign Targeting Wall Street & US Enterprises

The intrusion at Uber Freight is not an isolated event; it is part of a massive five-week voice phishing ("vishing") and data theft campaign that has targeted over 200 high-profile U.S. organizations.

Google Threat Intelligence and cybersecurity reports reveal that the threat cluster has systematically targeted major private equity, hedge fund, financial, and retail giants, including:

  • Private Equity & Finance: Blackstone Inc., Apollo Global Management Inc., KKR & Co. Inc., Bain Capital, TPG Inc., CME Group Inc., Bridgewater Associates, Clearlake Capital, and Moody’s Corp.

  • Hedge Funds: Citadel, Two Sigma Investments, Point72 Asset Management, and Millennium Management.

  • Retail & Enterprise: Levi Strauss & Co. (which disclosed a similar unauthorized access incident in SEC regulatory filings) and Uber Freight.

Uber Freight has involved federal law enforcement to assist in the ongoing forensic investigation. The company is expected to provide further updates regarding the scope of the accessed data during its next scheduled corporate briefing on September 15.

Instead of exploiting zero-day software vulnerabilities, attackers like UNC6671 penetrate these large organizations by making direct phone calls to employees' personal mobile phones, posing as company IT support staff. They instruct employees to log in through a fake portal (e.g., a passkeyhelpdesk domain) that employs Adversary-in-the-Middle (AiTM) infrastructure. Once employees log in, the attackers intercept session cookies and MFA tokens in real-time, completely bypassing MFA security.

Logistics networks like Uber Freight handle sensitive supply chain data, price lists, carrier databases, bills of lading, and customer contracts. Because global supply chains rely heavily on just-in-time delivery schedules, threat actors know that operational disruptions or leaks of critical customer data create significant leverage for ransom demands (typically up to $3 million USD per victim).

Cybercriminal groups often change their names from BlackFile to Helix, Redact, Pink, or Falcon to evade law enforcement tracking, avoid sanctions lists, and confuse security analysts. Despite the name changes, Google Threat Intelligence observes that they employ a suite of phishing tools and domain registration patterns. And the same script for automatically pulling data from the cloud was used in all of their campaigns.

 

 

 

💬 AI Content Assistant

Ask me anything about this article. No data is stored for your question.

Comments

Popular posts from this blog

When Agents Overreach Australian Case Study Sparks Debate over Autonomous AI Liability.

Etsy Layoffs 220 Roles Cut in Product and Engineering Restructure to Drive Faster Execution.

AI-Driven Cyberattacks Hit U.S. Corporate Giants Supply Chains Disrupted Across Healthcare and Retail.

Pavel Durov Reveals AI Message Manipulation and Extortion Behind Telegram Brief App Store Ban.

SpaceX Posts First Post-IPO Earnings Q2 Revenue Hits $7.8B as Starlink Profits Offset $15.8B AI Infrastructure Spend.

AMD Reports Record Q2 2026 Revenue Hits $11.5B as Data Center Sales Surge 107%.

Sony Reports Q1 FY2026 Revenue Hits ¥2.84 Trillion as Sensors and Music Offset Gaming Flatline.