Helix hackers claim Uber Freight breach, leak about a million files

- The Helix extortion gang listed Uber Freight on its leak site.
- It claims about a million stolen files.
- Uber Freight confirmed a data security incident.
The extortion gang Helix claims to have hacked Uber Freight, the logistics arm of the ride-hailing company.
They have begun leaking what they assert to be around one million stolen files. Uber Freight says the intrusion did not disrupt business.
Uber Freight confirms a breach but won’t discuss ransom
Uber Freight appeared on Helix’s data leak site on August 6, the date on which the gang began listing the company.
A few days later, the firm said it was investigating what it called a data security incident.
“We are investigating a data security incident involving unauthorized access to a portion of Uber Freight’s systems and repositories. The incident was identified, contained, and remediated, and we promptly engaged federal law enforcement,” the company said, adding that its systems were “secure and fully operational” with no impact on operations.
The company has not said whether it heard from the hackers at all or if any ransom changed hands.
Helix’s own tally runs to about a million files pulled from mailboxes, OneDrive accounts, the accounts receivable department, and other internal repositories. The leak listing adds accounts payable records and dispatch paperwork to that inventory.
Some of the documents appeared to be email exchanges between Uber Freight and its customers, with timestamps clustered around mid-June. The files could not be verified, and Uber Freight would not confirm or deny them.
Uber Freight says it is one of the largest managed-transportation networks in North America. It says it moves over $17 billion of goods in 18 million shipments each year.
Google ties Helix to a $10.6 million extortion crew
Google’s Threat Intelligence Group has linked Helix to a cluster it calls UNC6671, the same operation that also runs under the Redact, Pink, and Falcon banners. Google connects that group back to BlackFile, a brand retired in May 2026.
The intrusion method has been consistent across those labels. Operators call employees, often on personal mobiles, and impersonate IT helpdesk staff pushing an urgent, mandatory security migration, Google wrote in its August 7 report.
The calls lead targets to fake login pages where adversary-in-the-middle tooling collects passwords and multi-factor tokens, allowing access to cloud data in Microsoft 365 and Okta.
Google said an analysis of the group’s bitcoin wallets found at least $10.6 million was collected in ransoms from January to May. The crew has been targeting technology, transportation, and hospitality victims since June, veering away from the manufacturing, healthcare, and insurance targets it was working on earlier in the spring.
Cryptopolitan reported vishing attempts targeted Wall Street funds such as Point72, Citadel, Two Sigma, and Millennium this month, though the firms said client data remained secure.
In February, blockchain lender Figure Technology confirmed a breach after an employee was talked into granting file access. The breach was part of a campaign targeting companies that use Okta single sign-on, the same identity layer that UNC6671 targets.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Randa Moses
Randa Moses is an editor and reporter at Cryptopolitan covering tech, AI, robotics, crypto, scams, and hacks. She has worked in the crypto space since 2017. She held roles at Forward Protocol, AmaZix, and Cryptosomniac. Randa holds a degree in Electrical and Electronics Engineering from the University of Bradford.
















