AdobeStock/Gorodenkoff2

Uber Freight confirms cyberattack as hackers claim nearly 1 million files stolen

You can read this article in 6 minutes

Uber Freight has acknowledged unauthorised access to parts of its systems and data repositories. The Helix hacking group claims to have extracted almost one million files, including material from employee mailboxes, OneDrive accounts and accounts-receivable records. Uber Freight says the incident was contained and remediated, with no impact on operations. The case highlights why digital freight platforms are becoming increasingly valuable targets for cybercriminals.

The text you are reading has been translated using an automatic tool, which may lead to certain inaccuracies. Thank you for your understanding.

Key takeaways:

  • Uber Freight confirmed unauthorised access to parts of its systems and repositories.
  • Helix claims to have obtained nearly one million files from email accounts, OneDrive and accounts-receivable documentation.
  • The company has confirmed the security incident, but has not verified the alleged volume or authenticity of the files cited by the attackers.
  • Google says the Helix group, tracked as the UNC6671 cluster, uses methods including vishing and targets the transport sector.
  • The incident illustrates the risks created when logistics platforms concentrate large volumes of sensitive data in a single environment.

Uber Freight has confirmed unauthorised access to parts of its systems and repositories. In comments to FreightWaves, the company said the incident had been detected, contained and remediated, and that US federal law-enforcement agencies were involved. Uber Freight added that its operations had not been disrupted and that its systems were secure and fully operational.

Helix has made considerably broader claims. The group listed Uber Freight on its data-leak site and says it obtained almost one million files. The alleged material reportedly includes employee email data, Microsoft OneDrive files and documents related to accounts receivable.

Uber Freight has not confirmed those details. It also remains unclear whether the accessed data included information about customers, carriers, employees or suppliers. The distinction is material: the security incident itself has been confirmed, but the scale of the alleged data theft has not.

Why transport companies are becoming prime cyber targets

The incident matters to the transport and logistics sector because modern freight platforms hold far more than basic shipment details. Their databases may include transport orders, carrier information, routes, rates, payments, invoices, loading and delivery locations, as well as messages exchanged across the supply chain.

Access to that information could have consequences extending well beyond encrypted systems or a temporary operational outage. The data could potentially support highly targeted fraud, including impersonating business partners, sending convincing phishing messages, redirecting payments or attempting to steal loads.

Knowing who is carrying a particular shipment, where it is coming from, where it is headed and when it is due may be more valuable to a criminal than access to the company’s IT infrastructure alone.

Helix appears linked to a broader campaign

Google’s Threat Intelligence Group places Helix within a wider range of related cybercriminal activity tracked by researchers as UNC6671. Google says the same infrastructure and similar techniques are also associated with names including Redact, Pink, Falcon and, previously, BlackFile.

One of the group’s main tactics is vishing — phishing conducted by phone. Attackers reportedly pose as members of a company’s IT team and tell employees that they must urgently complete an account-security procedure. The victim is then directed to a fake login page designed to resemble the company’s internal portal.

Google says the attackers seek not only usernames and passwords, but also information that could help them bypass some multi-factor authentication controls. MFA requires users to verify their identity in addition to entering a password, for example with a code from an authentication app or another method.

After taking over an account, criminals may be able to download information from corporate cloud services such as Microsoft 365 and other business applications.

The transport-sector link is notable. Google researchers recorded increased interest from the group in June 2026, including in major companies operating in the transport, technology and hospitality sectors. However, Google has not identified Uber Freight as a confirmed victim of a specific UNC6671 attack. The method used to access the company’s systems is also unknown.

One platform can also mean concentrated risk

Transport digitisation has steadily brought more processes into shared environments: booking freight, selecting carriers, tracking shipments, communicating with partners, handling settlements and analysing data. This integration can save time and improve information flows, but it also places extensive operational data in a single location.

The Uber Freight incident underscores the exposure created by that concentration. The more supply-chain information a single platform stores, the more attractive it becomes to criminals.

The sector already faces cargo theft, carrier impersonation, fake transport orders, phishing and payment fraud. A data breach can make subsequent scams much more credible and harder to detect.

A criminal with access to genuine correspondence, employee names, order histories or document templates has a better chance of convincing a carrier or freight forwarder that they are dealing with a legitimate business partner.

Not every MFA method blocks phishing

Google recommends that companies adopt sign-in methods designed to resist common phishing attacks, including solutions based on the FIDO2 standard and passkeys. These tools reduce reliance on traditional passwords and make it harder for criminals to hijack access, even if an employee is persuaded to visit a fraudulent login page. Researchers also advise restricting access from untrusted devices and networks and monitoring cloud-service logins more closely.

Employee training is just as important. An attack may begin not with an advanced technical breach, but with a single phone call from someone claiming to work in IT. For transport and logistics companies, the message is clear: as more operations move onto digital platforms, cybersecurity becomes a direct part of protecting cargo and money.

The Uber Freight case does not prove that every file mentioned by the hackers was stolen. It does show, however, that criminals increasingly recognise the value of information stored in modern transport-management systems.

The key question is no longer only whether a company’s systems could be attacked. It is also what a criminal could do with information about its shipments if access were obtained.

Tags:

Also read