A hacker group calling itself Helix claimed it stole nearly one million Uber Freight files, and Uber Freight confirmed Wednesday that someone accessed part of its systems and repositories without permission, according to FreightWaves. The trucking-focused digital freight platform said it identified, contained and remediated the incident, but it has not verified Helix's files or identified the information involved.
What Uber Freight confirmed
An Uber Freight spokesperson told FreightWaves: "The incident was identified, contained and remediated." The spokesperson added, "We promptly engaged federal law enforcement." Uber Freight also said, "There has been no impact to Uber Freight's business operations," and "Our systems are secure and fully operational."
However, the response did not address whether customer, carrier, employee or vendor information appeared within the accessed repositories. Uber Freight has not disclosed notifications, forensic assistance, or a timeline for further findings. The company also has not confirmed contact with Helix. Uber Freight said it continues to investigate the incident.
Helix's claims
Helix listed Uber Freight on its data-leak site Aug. 6 and described material from several repositories, according to FreightWaves. The group claimed it accessed mailboxes, OneDrive accounts and accounts-receivable materials. Helix has not provided independent proof confirming the records' authenticity or scope, and Uber Freight has not confirmed the group's description of the material.
| Aspect | Status per FreightWaves |
|---|---|
| Helix's claimed file count | Nearly one million, unverified |
| Data-leak site listing date | Aug. 6 |
| Material claimed | Mailboxes, OneDrive accounts, accounts-receivable documents |
| Independent proof of theft | Not provided |
| Uber Freight verification of files | Not performed |
| Impact on business operations | None, per Uber Freight |
Google links Helix to a wider extortion campaign
Google Threat Intelligence Group tracks Helix as part of the UNC6671 activity cluster, FreightWaves reported. Researchers linked Helix, Falcon, Pink and Redact through shared phishing infrastructure. The group often impersonates corporate help desks through phone calls and fake login portals. Google does not identify Uber Freight as a confirmed UNC6671 victim.
Google reported that the cluster shifted toward transportation, technology and hospitality targets during June. Its researchers documented campaigns designed to capture employee credentials and multi-factor authentication tokens. Those credentials can allow criminals to access cloud tools and remove company information. Uber Freight has not identified how someone accessed its systems.
Why it matters for freight platforms
Freight platforms can hold shipping, carrier, payment and pricing data that criminals may target after unauthorized access, according to FreightWaves. Uber Freight confirmed the incident, but the company has not disclosed what information the intruder accessed.
For enterprise buyers and logistics technology managers, the unanswered questions — data scope, notification timing, access method — are the key procurement and risk-management concerns. The incident also underscores the credential-phishing tactics documented by Google, where help-desk impersonation and fake login portals are used to capture the multi-factor authentication tokens that protect cloud infrastructure.
Industry resources
FreightWaves offers Certified Fraud Compliance Officer (CFCO) coursework for transportation professionals, including practical lessons on identity verification, suspicious communications and fraud-response decisions. FreightWaves noted that Helix-linked actors pose as help-desk personnel to capture credentials, and verification steps can help teams identify a scam before granting system access. The company also promotes its Brokerage Compliance Symposium, covering fraud exposure, carrier liability, FMCSA rules, cargo theft and insurance gaps, alongside the F3 Awards Dinner and F3: Future of Freight Festival in Chattanooga, Tennessee.