2026 Uber Freight — Helix extortion listing; company investigating unauthorized access (~1M files claimed)
Data compromised
Helix claims ~1M files: email, OneDrive, accounts receivable/payable, dispatch materials; press reviewed alleged client correspondence (authenticity not company-confirmed). No attested individual census — recordsAffected 0.
Technical writeup
Company-confirmed investigation after Helix leak-site claim — On August 6, 2026 Helix listed Uber Freight and claimed nearly 1 million files from mailboxes, OneDrive, accounts receivable, and related repositories. Uber Freight told Reuters (Aug 11) and The Register (Aug 12) it is investigating unauthorized access to a portion of systems and repositories; the incident was identified, contained, and remediated; federal law enforcement was engaged; and business operations continued without disruption. The company did not authenticate Helix’s archive or publish a people count. Google links Helix to UNC6671-style cloud extortion (device-code phishing / M365 session theft). BreachHistory indexes companyConfirmed true for the investigation/access acknowledgment and recordsAffected 0 pending an attested individual census; the ~1M figure is an actor file claim.
Root cause
Company-confirmed unauthorized access to a portion of Uber Freight systems/repositories (contained/remediated per spokesperson); Helix extortion group claimed theft of nearly 1M files from mailboxes, OneDrive, AR, and related stores (UNC6671-linked cluster per Google)
References
- https://www.reuters.com/business/retail-consumer/uber-freight-says-its-investigating-cyber-incident-following-hacker-claims-2026-08-11/
- https://www.theregister.com/security/2026/08/12/uber-freight-keeps-on-trucking-after-extortion-crew-breaks-in/5286782
- https://mezha.net/eng/bukvy/0e9ebe55_helix_claims_it/
- https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments