BusinessCybersecurityNewswireTechnology

Uber Freight probes alleged data breach claimed by hackers

▼ Summary

– The Helix hacking group claimed responsibility for a cyberattack and data breach at Uber Freight, though Uber Freight stated business operations were unaffected.
– Helix has targeted transportation, financial, and private equity firms, exfiltrating cloud data and threatening to publish it unless ransoms are paid.
– The hackers allegedly stole mailboxes, cloud storage, accounts payable files, and dispatch documents from Uber Freight, with some files appearing to show customer email correspondence.
– Uber Freight has not confirmed whether it received hacker correspondence or paid a ransom.
– Google links Helix to the broader UNC6671 collective, which uses voice phishing to reset employee passwords, and estimates the gang earned at least $10.6 million in ransoms from January to May.

A cyber extortion group has claimed responsibility for an attack on Uber Freight, the logistics arm of the ride-hailing giant, allegedly stealing corporate data and threatening to release it.

Uber Freight has confirmed to Reuters that its business operations remain unaffected and that all systems are functioning normally. The company had not responded to TechCrunch’s inquiries at the time of publication.

This incident marks the latest in a string of breaches attributed to the Helix hacking group, a collective that has spent much of the year targeting transportation firms, financial institutions, and investment houses. The group’s methodology typically involves infiltrating cloud environments, siphoning off large volumes of sensitive files, and then demanding a ransom under the threat of public exposure.

On its dedicated leak site, a platform used to host stolen data, Helix claims to have accessed Uber Freight’s mailboxes, cloud storage repositories, accounts payable records, and dispatch documents. TechCrunch reviewed a sample of the files, which appear to include email correspondence between Uber Freight and several of its clients. While the authenticity of the documents could not be independently verified, the timestamps suggest they were generated around mid-June.

Uber Freight has not disclosed whether it has received any direct communication from the attackers or whether any ransom demand has been paid.

Earlier this week, Google revealed that Helix operates under a broader umbrella of hacker collectives tracked internally as UNC6671. The group is known for its reliance on social engineering tactics, particularly voice phishing, a technique where attackers call corporate IT helpdesks and impersonate employees to request password resets. Security experts have repeatedly cautioned that these methods, though unsophisticated, remain alarmingly effective at exploiting human error to gain unauthorized access.

According to Google’s analysis of the group’s bitcoin wallets, Helix has collected at least $10.6 million in ransom payments between January and May of this year.

(Source: TechCrunch)

Topics

cybersecurity breach 98% ransomware extortion 95% corporate data theft 93% helix hacking group 92% social engineering attacks 90% supply chain logistics 88% cloud security vulnerabilities 85% incident response 82% data leak site 80% transportation sector security 78%