"We are investigating a data security incident involving unauthorized access to a portion of Uber Freight's systems and repositories," an Uber Freight spokesperson told The Register, in a statement that also said the company had "identified, contained, and remediated" the intrusion and that its systems were "secure and fully operational."
Uber Freight's public posture and operational impact
Uber Freight — described on its website as the ubiquitous ride‑sharing company's lesser‑known logistics arm and claiming to manage 18 million shipments carrying more than $17 billion worth of goods each year — acknowledged an investigation after the company appeared on an extortion group's data‑leak site. The spokesperson told The Register the incident had not disrupted daily operations: "There has been no impact to Uber Freight's business operations, which continue in the normal course without disruption."
The statement added the company "promptly engaged federal law enforcement" and said the incident had been "identified, contained, and remediated." Uber Freight did not confirm or deny whether material posted by the extortion group was authentic.
Helix's claim: nearly 1 million files and staged releases
On August 6 the Helix extortion group listed Uber Freight on its data leak site. Helix claimed to have stolen "nearly 1 million files" from employee mailboxes, OneDrive accounts, the accounts receivable department, and "other repositories," and released material in stages.
The Register, reporting on the incident, said it did not download the files Helix released; Uber Freight did not verify the authenticity of the posted material, according to that report.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildConnections to BlackFile and the UNC6671 cluster, per Google Threat Intelligence Group
Researchers have linked Helix to infrastructure associated with BlackFile, an extortion brand that retired its name in May, and to several recently established extortion brands. Google Threat Intelligence Group (GTIG) said Helix shares infrastructure with brands named Pink, Redact, and Falcon, and that it tracks the wider cluster as UNC6671.
GTIG noted that multiple brands have emerged within the cluster and said the reasons are unclear. The group offered possible explanations, writing the strategy could "compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout." GTIG also suggested other plausible explanations, including internal disagreements over finances and operational security, a division of labor that keeps core members focused on intrusion and data theft while outsourcing negotiations, or simply different groups using the same commoditized phishing tools.
Tactics described by GTIG: vishing, device code phishing, cloud siphoning, Okta targeting
GTIG described how operators associated with UNC6671 frequently gain initial access. The group said operators "often use vishing to gain an initial foothold," posing as IT helpdesk staff overseeing mandatory security migrations and contacting employees on their personal phones. They then employ device code phishing to obtain credentials and authenticated sessions.
According to GTIG, once authenticated sessions are obtained the operators have siphoned data from cloud services such as Microsoft 365, and they have also targeted Okta identity infrastructure.
What this means for technologists, procurement leaders, and affected enterprises
- Technologists and security teams: GTIG's account highlights social engineering vectors — vishing and device code phishing — as primary initial access methods for UNC6671‑linked actors. Teams responsible for identity and cloud protections will likely note Microsoft 365 and Okta as specific targets described by researchers.
- Procurement and operations leaders at large logistics customers: Uber Freight's website figures — 18 million shipments and more than $17 billion in goods annually — underscore the scale of operations the legal and risk teams may be considering as they evaluate downstream exposure and contractual obligations.
- Affected enterprises and incident responders: Uber Freight reported that the incident was "identified, contained, and remediated" and that federal law enforcement was engaged. At the same time, the extortion group's staged postings and the lack of third‑party verification of the leaked files leave questions about data scope and authenticity that responders must address during post‑incident review.
The published record ties a single intrusion claim to a recognized cluster of extortion brands and a specific set of social‑engineering techniques, while leaving other core details unsettled. Helix's assertion of "nearly 1 million files" and the GTIG account of shared infrastructure and tactics provide concrete elements for investigators and customers to examine; at the same time, the extent to which the posted material reflects what Uber Freight's systems actually contained remains unverified in public reporting.
Original story: https://www.theregister.com/security/2026/08/12/uber-freight-keeps-on-trucking-after-extortion-crew-breaks-in/5286782




