Uber Freight investigates data breach claimed by Helix hacking group

Original: Uber Freight reportedly investigating after hacking group claims data breach

Why This Matters

The breach highlights the growing threat of social engineering-based ransomware attacks on logistics and transportation firms.

Uber Freight is investigating a cyberattack claimed by the Helix hacking group, which says it stole mailboxes, cloud storage, accounts payable records, and dispatch documents. The company told Reuters its systems are running normally with no impact on business operations.

The Helix hacking and extortion group has claimed responsibility for a cyberattack and data breach targeting Uber Freight, the logistics subsidiary of ride-sharing giant Uber. An Uber Freight spokesperson told Reuters, which first reported the incident, that business operations were unaffected and systems were running normally. The company did not respond to TechCrunch's questions.

On its data leak site, Helix claims to have exfiltrated mailboxes, cloud storage drives, accounts payable files, and dispatch documents. Some files reviewed by TechCrunch appear to show email correspondence between Uber Freight and customers, though their authenticity could not be verified. The files appear dated around mid-June.

Helix has targeted transportation companies, financial institutions, and private equity firms throughout 2026, relying on social engineering tactics such as voice phishing — calling IT helpdesks to request employee password resets. Google identified Helix this week as part of a broader collective it tracks as UNC6671, and reported that a review of the group's bitcoin wallets shows at least $10.6 million collected in ransom payments between January and May 2026. It remains unclear whether Uber Freight received or responded to any ransom demand.

Source

techcrunch.com — Read original →