Uber Freight Investigates Major Data Breach Claim by Helix Hacking Group
A hacking group known as Helix claims to have exfiltrated approximately one million files from Uber Freight's systems, posting details on a dark web leak site, prompting an investigation by the logistics giant.
✨ This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more
Listen to this story

A hacking and extortion group, identified as Helix and tracked by Google's Threat Intelligence Group under the umbrella actor UNC6671, claims to have exfiltrated approximately one million files from Uber Freight's systems, posting details on a dark web leak site on August 6, 2026. While Uber Freight stated on August 11, 2026, that it is investigating the data security incident involving unauthorized access, the company has declined to confirm the authenticity of the posted data or whether it has engaged in contact with the hackers, emphasizing that its business operations remain unaffected and systems are secure and fully operational. This incident highlights a growing trend of sophisticated social engineering attacks targeting critical logistics and financial infrastructure, with Helix and its aliases (Falcon, Pink, Redact) known for voice-phishing campaigns impersonating IT staff to gain access to large financial firms, having reportedly received around $10 million in Bitcoin this year from various extortion demands.
The alleged breach at Uber Freight, Uber Technologies' logistics subsidiary launched in 2017 and expanded with the $2.25 billion acquisition of Transplace in 2021, matters significantly due to the sensitive nature of data handled within the freight brokerage and transportation management sector. Uber Freight's systems typically contain contract details, pricing agreements, and carrier records, making any compromise a substantial risk for operational disruption, competitive disadvantage, and erosion of trust among its vast network of shippers and carriers. While the company asserts no impact on current business operations, the potential exposure of such data could lead to severe financial and reputational damage, particularly if details of ongoing contracts or proprietary logistics strategies fall into the wrong hands. The incident also underscores the increasing vulnerability of supply chains, which are becoming prime targets for cybercriminals leveraging AI-driven threats and exploiting third-party vendor risks. A 2026 report indicates that 26% of businesses experienced a cyber incident originating from their supply chain in the past year, with 48% of IT decision-makers admitting to working with suppliers despite known security concerns.
This incident echoes a difficult history for Uber regarding data security and breach disclosure. In 2016, Uber concealed a breach affecting 57 million users and drivers, paying hackers $100,000 to delete the data and sign a non-disclosure agreement, a cover-up that led to a $148 million settlement with U.S. states in 2018 and the conviction of its former Chief Security Officer, Joe Sullivan, in 2022 for obstruction of justice. More recently, in 2024, the Dutch data protection authority fined Uber €290 million over transfers of driver data to the U.S.. This pattern of security lapses and transparency issues sets a challenging precedent for Uber Freight's current investigation, placing immense pressure on the subsidiary to demonstrate a more transparent and robust response. In comparison to rivals, the logistics sector as a whole faces escalating cyber threats; for instance, Ceva Logistics recently experienced a cyberattack between July 29 and August 1, 2026, disrupting operations at eight European warehouses and exposing customer data for major retailers and gaming platforms. Such incidents highlight that while Uber Freight has invested in security hardening, vulnerability scans, and third-party monitoring, the sophisticated social engineering tactics employed by groups like Helix pose a threat that traditional technical defenses alone may struggle to counter effectively.
Looking ahead, the Uber Freight incident will likely intensify scrutiny on cybersecurity practices across the entire logistics and transportation industry. With new regulatory mandates taking effect in 2026, such as California's requirement for data breach notifications within 30 days of discovery and attorney general notification within 15 days for breaches affecting over 500 residents, companies face compressed response timelines and increased accountability. The rise of AI-driven threats and the increasing interconnectedness of supply chains mean that proactive, continuous monitoring and adaptive security strategies are no longer optional but critical for survival. This will necessitate greater collaboration between logistics providers, their clients, and cybersecurity experts to build more resilient systems capable of anticipating and preventing sophisticated attacks, rather than merely reacting to them. For Uber Freight, the coming months will be crucial in restoring confidence, not just through technical remediation but through transparent communication and a demonstrable commitment to safeguarding sensitive data, ultimately shaping its competitive standing in an increasingly digitized and vulnerable global supply chain.