Helix, an extortion group that researchers tie to the retired BlackFile ransomware brand, claims it stole nearly a million files from Uber Freight, the logistics arm of the ride-hailing giant. The crew listed the company on its leak site on August 6, saying the haul came from employee mailboxes, OneDrive accounts, and the accounts receivable department.
Uber Freight confirmed to The Register that it is investigating a data security incident involving unauthorized access to parts of its systems and repositories. A spokesperson said the breach was identified, contained, and remediated, and that federal law enforcement was engaged. Operations never stopped, with the company describing its systems as secure and fully operational.
The trucking platform says it manages 18 million shipments carrying more than $17B in goods each year, making it one of North America’s largest managed transportation networks. That scale makes it an attractive target for extortion crews that have recently shifted toward technology, transportation, and hospitality victims.
Google Threat Intelligence Group tracks Helix alongside the Pink, Redact, and Falcon brands under the cluster UNC6671. Operators typically open with vishing, posing as IT helpdesk staff, then use device code phishing to steal credentials and sessions for cloud services such as Microsoft 365. Uber Freight has not confirmed whether the leaked material is authentic.
The incident adds to a growing list of logistics and fleet operators hit this year as attackers chase the supply chain data carriers hold, and it shows that even well-known freight brands remain reachable through cloud credential theft.