Uber Freight is investigating a cybersecurity incident after a hacking and extortion group claimed it stole a massive collection of files from the logistics company, although Uber Freight says its business operations remain unaffected.
Helix Claims Nearly 1 Million Uber Freight Files
The scale of the alleged theft remains unverified, but the hackers are claiming a substantial breach.
Reuters reported that Helix posted what it described as nearly 1 million Uber Freight files on its website on August 6. Company spokesperson Sam Hallock did not confirm whether the data published by the group was authentic or say whether Uber Freight had communicated with the attackers.
TechCrunch said Helix claims the stolen material includes employee mailboxes, cloud-storage drives, accounts-payable files and dispatch documents. Some of the posted files appeared to contain email correspondence between Uber Freight and several customers, with documents apparently dating to around mid-June, although the publication could not independently verify their authenticity.
Uber Freight Says Operations Remain Normal
Despite acknowledging unauthorized access, Uber Freight says the incident has not disrupted its logistics business.
Reuters quoted Hallock as saying there had been no impact on Uber Freight’s business operations and that its systems remained secure and fully operational. The company promptly contacted federal law enforcement after discovering the incident.
TechCrunch likewise reported that Uber Freight shared that its operations were running normally, while noting that the company had not answered TechCrunch’s questions about whether it received a ransom demand or paid the hackers.
Helix Linked to Wider Extortion Campaign
The Uber Freight incident appears to be part of a larger campaign targeting prominent businesses.
Helix is one of several names associated with a broader hacking cluster that has recently targeted companies including Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s.
Google tracks the broader hacker collective as UNC6671 and described Helix as part of a series of attacks against transportation companies, financial institutions and private-equity firms. The group’s approach reportedly involves stealing large volumes of cloud-hosted information and threatening to publish it unless the victim pays.
Voice Phishing Helps Attackers Get Inside
The attacks do not necessarily begin with advanced malware.
TechCrunch reported that Helix and related hackers use social-engineering methods such as voice phishing, including calling corporate IT help desks and persuading staff to reset employee passwords. Google’s analysis cited by TechCrunch found that cryptocurrency wallets associated with the group received at least $10.6 million in ransom payments between January and May 2026.
Uber Freight was among dozens of prominent US companies and financial institutions targeted in recent extortion attempts.
The investigation now centers on what data Helix actually obtained, how the unauthorized access occurred and whether the posted files are genuine. Uber Freight’s operations may be continuing normally, but the hackers’ claim of nearly one million files shows how a cyberattack can become a serious data-exposure and extortion problem even when the company’s day-to-day business remains online.