The extortion gang Helix claims to have hacked Uber Freight, the logistics arm of the ride-hailing company.
They have begun leaking what they assert to be around one million stolen files. Uber Freight says the intrusion did not disrupt business.
Uber Freight confirms a breach but wonβt discuss ransom
Uber Freight appeared on Helixβs data leak site on August 6, the date on which the gang began listing the company.
A few days later, the firm said it was investigating what it called a data security incident.
βWe are investigating a data security incident involving unauthorized access to a portion of Uber Freightβs systems and repositories. The incident was identified, contained, and remediated, and we promptly engaged federal law enforcement,β the company said, adding that its systems were βsecure and fully operationalβ with no impact on operations.
The company has not said whether it heard from the hackers at all or if any ransom changed hands.
Helixβs own tally runs to about a million files pulled from mailboxes, OneDrive accounts, the accounts receivable department, and other internal repositories. The leak listing adds accounts payable records and dispatch paperwork to that inventory.
Some of the documents appeared to be email exchanges between Uber Freight and its customers, with timestamps clustered around mid-June. The files could not be verified, and Uber Freight would not confirm or deny them.
Uber Freight says it is one of the largest managed-transportation networks in North America. It says it moves over $17 billion of goods in 18 million shipments each year.
Google ties Helix to a $10.6 million extortion crew
Googleβs Threat Intelligence Group has linked Helix to a cluster it calls UNC6671, the same operation that also runs under the Redact, Pink, and Falcon banners. Google connects that group back to BlackFile, a brand retired in May 2026.
The intrusion method has been consistent across those labels. Operators call employees, often on personal mobiles, and impersonate IT helpdesk staff pushing an urgent, mandatory security migration, Google wrote in its August 7 report.
The calls lead targets to fake login pages where adversary-in-the-middle tooling collects passwords and multi-factor tokens, allowing access to cloud data in Microsoft 365 and Okta.
Google said an analysis of the groupβs bitcoin wallets found at least $10.6 million was collected in ransoms from January to May. The crew has been targeting technology, transportation, and hospitality victims since June, veering away from the manufacturing, healthcare, and insurance targets it was working on earlier in the spring.
Cryptopolitan reported vishing attempts targeted Wall Street funds such as Point72, Citadel, Two Sigma, and Millennium this month, though the firms said client data remained secure.
In February, blockchain lender Figure Technology confirmed a breach after an employee was talked into granting file access. The breach was part of a campaign targeting companies that use Okta single sign-on, the same identity layer that UNC6671 targets.
If you're reading this, youβre already ahead. Stay there with our newsletter.



















English (US)