Uber Freight investigates cyberattack claimed by Helix hacking group
Uber Freight is assessing a breach attributed to the Helix group, which claims to have accessed mailboxes and financial records, while Google tracks the collective as UNC6671 amid rising ransom demands.

Uber Freight is investigating a cyberattack alleged by the Helix hacking group, which claims to have exfiltrated sensitive data from the ride-sharing giant’s logistics subsidiary. The incident follows a post on the group’s data leak site, where hackers asserted they had accessed mailboxes, cloud storage files, accounts payable documents, and dispatch records.
A spokesperson for Uber Freight confirmed to Reuters that the company is aware of the incident and is conducting an internal review. The company stated that its business operations and systems remain unaffected and are running normally. Uber Freight did not immediately respond to further questions from TechCrunch regarding the specifics of the breach or whether it had received correspondence from the attackers.
The Helix group, also tracked by Google as the UNC6671 collective, has reportedly targeted transportation companies, financial institutions, and private equity firms throughout the year. The group is known for extracting large volumes of data from cloud environments and threatening to publish the information unless ransoms are paid. Files viewed by TechCrunch appear to show email correspondence between Uber Freight and several customers, dated around mid-June, though the authenticity of these documents has not been independently verified.
Security researchers have highlighted that Helix relies heavily on social engineering tactics, including voice phishing, to compromise systems. This method involves calling IT helpdesks to request password resets, a technique that, while considered rudimentary, has proven effective in tricking staff into granting access to sensitive infrastructure.
According to a blog post from Google, a review of the group’s bitcoin wallets indicates that Helix has collected at least $10.6 million in ransom payments between January and May this year. The logistics subsidiary is the latest target in a recent wave of hacks conducted by the group, raising questions about the security posture of major transport operators.

