iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Cybersecurity ›› Uber Freight Confirms Cyber Incident After Hackers Claim Nearly 1 Million Files

Uber Freight Confirms Cyber Incident After Hackers Claim Nearly 1 Million Files

Hacker group Helix claimed it stole nearly one million Uber Freight files, and Uber Freight confirmed that someone accessed part of its systems without permission. The company says it contained and remediated the incident, but has not verified the files or disclosed what data was involved. Google Threat Intelligence Group links Helix to the UNC6671 extortion cluster targeting transportation firms.

iG
iGEN Editorial
August 13, 2026
Uber Freight Confirms Cyber Incident After Hackers Claim Nearly 1 Million Files

A hacker group calling itself Helix claimed it stole nearly one million Uber Freight files, and Uber Freight confirmed Wednesday that someone accessed part of its systems and repositories without permission, according to FreightWaves. The trucking-focused digital freight platform said it identified, contained and remediated the incident, but it has not verified Helix's files or identified the information involved.

What Uber Freight confirmed

An Uber Freight spokesperson told FreightWaves: "The incident was identified, contained and remediated." The spokesperson added, "We promptly engaged federal law enforcement." Uber Freight also said, "There has been no impact to Uber Freight's business operations," and "Our systems are secure and fully operational."

However, the response did not address whether customer, carrier, employee or vendor information appeared within the accessed repositories. Uber Freight has not disclosed notifications, forensic assistance, or a timeline for further findings. The company also has not confirmed contact with Helix. Uber Freight said it continues to investigate the incident.

Helix's claims

Helix listed Uber Freight on its data-leak site Aug. 6 and described material from several repositories, according to FreightWaves. The group claimed it accessed mailboxes, OneDrive accounts and accounts-receivable materials. Helix has not provided independent proof confirming the records' authenticity or scope, and Uber Freight has not confirmed the group's description of the material.

Aspect Status per FreightWaves
Helix's claimed file count Nearly one million, unverified
Data-leak site listing date Aug. 6
Material claimed Mailboxes, OneDrive accounts, accounts-receivable documents
Independent proof of theft Not provided
Uber Freight verification of files Not performed
Impact on business operations None, per Uber Freight

Google links Helix to a wider extortion campaign

Google Threat Intelligence Group tracks Helix as part of the UNC6671 activity cluster, FreightWaves reported. Researchers linked Helix, Falcon, Pink and Redact through shared phishing infrastructure. The group often impersonates corporate help desks through phone calls and fake login portals. Google does not identify Uber Freight as a confirmed UNC6671 victim.

Google reported that the cluster shifted toward transportation, technology and hospitality targets during June. Its researchers documented campaigns designed to capture employee credentials and multi-factor authentication tokens. Those credentials can allow criminals to access cloud tools and remove company information. Uber Freight has not identified how someone accessed its systems.

Why it matters for freight platforms

Freight platforms can hold shipping, carrier, payment and pricing data that criminals may target after unauthorized access, according to FreightWaves. Uber Freight confirmed the incident, but the company has not disclosed what information the intruder accessed.

For enterprise buyers and logistics technology managers, the unanswered questions — data scope, notification timing, access method — are the key procurement and risk-management concerns. The incident also underscores the credential-phishing tactics documented by Google, where help-desk impersonation and fake login portals are used to capture the multi-factor authentication tokens that protect cloud infrastructure.

Industry resources

FreightWaves offers Certified Fraud Compliance Officer (CFCO) coursework for transportation professionals, including practical lessons on identity verification, suspicious communications and fraud-response decisions. FreightWaves noted that Helix-linked actors pose as help-desk personnel to capture credentials, and verification steps can help teams identify a scam before granting system access. The company also promotes its Brokerage Compliance Symposium, covering fraud exposure, carrier liability, FMCSA rules, cargo theft and insurance gaps, alongside the F3 Awards Dinner and F3: Future of Freight Festival in Chattanooga, Tennessee.


Sources: FreightWaves

Keep Reading

Recommended Stories

FBI Exposes $1 Billion Cargo Theft Network Amid Crackdown on CDL Training Schools Supply Chain

FBI Exposes $1 Billion Cargo Theft Network Amid Crackdown on CDL Training Schools

FreightWaves reports on a $1 billion cargo theft network uncovered by the FBI and federal crackdowns on 75 CDL training schools suspected of widespread fraud. The story highlights sophisticated criminal methods, driver safety risks, and law enforcement responses.

July 21, 2026
Can OEM axle weight data and satellite imagery help identify cargo theft? Supply Chain

Can OEM axle weight data and satellite imagery help identify cargo theft?

A study by freight analytics firm Class8 demonstrates how combining OEM axle weight data from truck suspension systems with satellite imagery analysis can flag potential cargo theft events. The three-stage pipeline evaluated 3.26 million unload events and classified over 42,000 as high or critical risk, with hotspots in Arizona, North Dakota, and New Mexico.

June 29, 2026
Freight's Security Shift: Speed Alone No Longer Enough as Fraud Threats Rise Logistics

Freight's Security Shift: Speed Alone No Longer Enough as Fraud Threats Rise

The freight industry faces rising cargo theft and identity fraud, forcing a shift from trust-based operations to verified processes. Malcolm Harris of What the Truck and Verisk CargoNet highlight the need for structured verification combining technology and human judgment.

June 12, 2026
Cyberattack on Refrigerated Warehouse Disrupts Glico, KFC Japan, and Sushi Deliveries Technology

Cyberattack on Refrigerated Warehouse Disrupts Glico, KFC Japan, and Sushi Deliveries

A cyberattack on Japan's largest refrigerated warehouse operator, Nichirei, has disrupted supplies for Ezaki Glico, KFC Japan, and Kura Sushi. The incident highlights critical vulnerabilities in food supply chain technology and logistics networks.

July 16, 2026