Skip to main content
Emerging ThreatsData Breaches

Uber Freight Probes Data Breach Claims by Helix Hacking Group

Logistics setting with laptop and shipping containers in background.

Approximately 1 million files — that is the scale claimed by a hacking group calling itself Helix after posting data it says were stolen from Uber Freight.

Helix’s claim of "approximately 1 million files"

The hacking group Helix publicly asserted it had taken roughly 1 million files from Uber Freight and posted those files on its website, according to reports from Reuter. The claim is the most concrete figure in circulation about the incident and is the focal point of public and technical scrutiny.

Uber Freight's investigation and statement

Uber Freight has acknowledged an investigation into unauthorized access, saying the company is examining "unauthorized access to parts of its systems and repositories." The company has not confirmed the authenticity of the materials published by Helix, and its public remark is limited to the fact of an investigation rather than a definitive description of what was exposed.

GTIG ties Helix to other recent incidents, including Blackstone and Apollo Global Management

The Google Threat Intelligence Group (GTIG) is cited in reporting that identifies Helix as one of several threat actors associated with other recent incidents. GTIG’s assessment links Helix to reported incidents against Blackstone, Apollo Global Management, and additional entities, placing the Uber Freight claim alongside a pattern GTIG has observed.

Authenticity and timeline uncertainty

Key details remain unresolved in public accounts. Reuter’s report and Uber Freight’s statement leave two points explicit: it is unclear whether the data posted by Helix are authentic, and Uber Freight has not shared when it was informed of the alleged breach. The organization "has also not shared ... if company spokespeople have interacted with the hacking group," leaving the timeline of discovery and any communications opaque in available reporting.

What this means for technologists and security teams, Uber Freight customers, and procurement leaders

  • Technologists and security teams: They will be watching for confirmation of authenticity and technical indicators tied to the claim that "parts of [Uber Freight's] systems and repositories" were accessed. GTIG’s linkage of Helix to other incidents frames the claim as part of a broader set of events GTIG has tracked.
  • Uber Freight customers and partners: Shippers and logistics partners named or implied in discussions around Uber Freight should expect the company’s investigation to determine whether any of their data were involved; public statements so far confirm an internal probe but do not confirm exposure.
  • Procurement leaders and enterprises that contract with freight providers: The GTIG attribution to incidents affecting Blackstone, Apollo Global Management, and others highlights why organizations that rely on third-party logistics and data handling may monitor disclosures from both their vendors and threat intelligence groups.

The publicly available record establishes three concrete facts: Helix claims to have posted roughly 1 million files, Uber Freight says it is investigating unauthorized access to parts of its systems and repositories, and GTIG has associated Helix with other recent incidents including those reported against Blackstone and Apollo Global Management. Beyond those points, essential questions remain — chiefly whether the posted material is authentic and when Uber Freight first learned of the intrusions — because the company "has also not shared when it was informed of the breach or if company spokespeople have interacted with the hacking group."

As the situation develops, confirmation of authenticity and a clearer timeline from Uber Freight and independent investigators will determine whether the claim amounts to a verified large-scale exposure or a staged posting with uncertain provenance. For now, the record is dominated by the Helix claim, Uber Freight’s investigation notice, and GTIG’s broader linkage to similar incidents.

https://www.securitymagazine.com/articles/102484-uber-freight-investigates-data-security-concern