Uber Freight Investigates Cyber Incident Following Helix Hacker Group Breach Claims
Uber Freight, the logistics arm of ride-hailing company Uber, is looking into a potential cybersecurity incident after an extortion group claimed responsibility for breaching its network and stealing sensitive corporate records. While the gang asserts it exfiltrated cloud data and communication logs, company representatives have stated that daily operations and core systems remain functional and unaffected.
What Happened
The cyberattack and breach were claimed by an extortion crew known as the Helix hacking group, which announced the alleged intrusion on its data leak platform. According to the hackers’ claims, the stolen materials include employee mailboxes, cloud storage drives, accounts payable records, and dispatch paperwork belonging to Uber Freight.
Reports indicate that some files displayed on the leak site appear to show correspondence between Uber Freight and multiple business clients, with records dated around mid-June. A spokesperson for Uber Freight informed Reuters, which first reported on the matter, that the company’s business operations experienced no disruption and all systems have continued to run as normal. The logistics firm has not confirmed whether it received ransom demands or engaged in financial negotiations with the group.
Key Highlights
- Extortion Claim: The Helix hacking group took credit for accessing Uber Freight’s cloud systems and exfiltrating company documents.
- Alleged Data Taken: Compromised records reportedly involve mailboxes, dispatch paperwork, accounts payable files, and cloud storage contents.
- Operational Status: Uber Freight stated that the incident has caused no operational downtime, with all systems functioning normally.
- Hacker Profile: Google identifies Helix as part of a cyber group tracked under the moniker UNC6671, which has targeted private equity, financial firms, and transportation companies.
- Financial Impact: Analysis of cryptocurrency wallets linked to the threat actors showed at least $10.6 million collected in ransom payments between January and May.
Why This Matters
The incident reflects a broader pattern of cyber incidents targeting enterprise logistics and transportation networks. Threat intelligence from Google indicates that the Helix group frequently employs social engineering techniques, specifically voice phishing, by contacting internal IT helpdesks to trick staff into resetting user passwords. These tactics allow attackers to gain unauthorized entry into cloud environments, where large volumes of sensitive customer files and financial documentation are stored, subsequently using the threat of public release to demand extortion payments.
What to Watch Next
Key developments will depend on the findings of Uber Freight’s ongoing review, including verification of whether company data was compromised. Observers will also be watching whether any additional stolen records are leaked publicly or if official disclosures are made regarding communication with the extortion group.
Frequently Asked Questions
What systems or files were allegedly affected at Uber Freight?
The Helix group claims to have stolen dispatch documents, accounts payable files, mailboxes, and cloud storage data. Uber Freight has noted that its operational systems are running normally without interruption.
How does the Helix hacking group gain access to networks?
According to security research from Google, the group, tracked as part of UNC6671, relies on social engineering tactics like voice phishing. Attackers call corporate IT helpdesks to request password resets, securing administrative access to cloud environments.
Did Uber Freight pay a ransom to the hackers?
Uber Freight has not stated whether it received direct communications from the extortionists or if any ransom payment was made.
Source: TechCrunch, reporting based on statements provided to Reuters and cybersecurity analysis from Google.
