Uber Freight said it is investigating a data security incident involving unauthorized access to parts of its systems and repositories after the Helix extortion group listed the company on its leak site and claimed to have posted nearly 1 million files online. Reports said the alleged haul included data from mailboxes, OneDrive accounts, and the accounts receivable department, although Uber Freight did not confirm the authenticity of the leaked material. The company said the intrusion was identified, contained, and remediated, and that business operations were not disrupted.
Uber Freight also said it had engaged federal law enforcement as the incident drew links to a wider campaign targeting prominent U.S. companies. Researchers cited in the reports tied Helix to a broader extortion ecosystem associated with BlackFile and the UNC6671 cluster, which has been linked to credential theft through vishing and device-code phishing and to follow-on access into cloud services such as Microsoft 365 and, in some cases, Okta environments.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Reuters reported on August 6 that Uber was among dozens of prominent U.S. businesses and financial institutions targeted in recent extortion attempts. The report named firms including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s.
In an August 6 blog post, Google Threat Intelligence said Helix is one of several names associated with a cluster of high-profile hacking activity. Google said Helix shares infrastructure with other extortion brands and tracks the broader cluster as UNC6671.
On August 6, the Helix extortion group listed Uber Freight on its leak site and claimed to have posted nearly 1 million files. Helix said the material came from sources including mailboxes, OneDrive accounts, accounts receivable, and other repositories.
Researchers said that during April and May, UNC6671-linked brands focused on manufacturing, real estate, healthcare, and insurance, but since June they have favored technology, transportation, and hospitality targets. This contextual shift helps place Uber Freight within a broader targeting trend.
Researchers said the BlackFile extortion brand retired its name in May. Later reporting linked Helix to infrastructure associated with BlackFile.
Uber Freight disclosed that it is investigating a data security incident involving unauthorized access to part of its systems and repositories. The company said the incident was identified, contained, and remediated, federal law enforcement was engaged, and business operations were not disrupted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
securitymagazine.com
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourcetheregister.com
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.