Key takeaways
- Helix stole mailboxes, cloud storage, and dispatch documents from Uber Freight, claiming them on its extortion portal without company confirmation of ransom demands.
- Google linked Helix to the UNC6671 collective and documented at least $10.6 million in ransom payments between January and May 2026, primarily through voice phishing attacks.
- Uber Freight confirmed the breach but stated operations were unaffected, raising questions about the full scope of exposure to customer data and business processes.
Uber Freight, the logistics subsidiary of the ride-sharing platform, has fallen victim to a cyberattack by Helix, a criminal gang that uses stolen data as leverage for extortion. The group announced the breach on its public data leak site this week, claiming to have extracted corporate email accounts, cloud storage files, and operational documents from the company’s systems. Uber Freight confirmed the incident to Reuters, though the company stated that operations continued without disruption and that its systems remained functional throughout the attack.
The scope of the theft
According to Helix’s own disclosure, the attackers gained access to multiple categories of sensitive material from Uber Freight’s infrastructure. The stolen data includes email mailboxes, cloud storage drives, files tied to accounts payable processes, and dispatch documentation. TechCrunch reviewed samples of the exfiltrated files, which appeared to contain email exchanges between Uber Freight personnel and customers; some correspondence was dated around mid-June, though the outlet could not independently verify the authenticity of the materials at the time of reporting.
The breach underscores the vulnerability of cloud environments to credential-based attacks. Helix operates by exfiltrating large volumes of data and then threatening to publish it publicly unless the victim company pays a ransom. The group has posted evidence of the theft to its data leak portal, a tactic designed to create urgency and credibility for its extortion demands.
Uber Freight has not disclosed whether it received explicit ransom communications from the attackers or whether any payment was made. The company told Reuters only that its operations were unaffected by the incident.
Understanding Helix and its methods
Identity and tracking
Google security researchers identified Helix earlier this week as part of a broader criminal collective that the company tracks under the identifier UNC6671. The disclosure came in a Google blog post that outlined the group’s operational tactics and financial gains. Helix has targeted transportation companies, financial institutions, and private equity firms throughout 2026, making it one of the year’s most active extortion-focused hacking collectives.
Social engineering as the entry point
The group relies heavily on social engineering techniques to breach corporate networks, with voice phishing being a primary method. Voice phishing involves attackers calling corporate IT helpdesks and impersonating employees to request password resets or other credential-related assistance. Security researchers have long noted that these attacks, despite their simplicity and lack of technical sophistication, prove remarkably effective at manipulating human judgment. IT support staff, under pressure to help employees who claim to be locked out, frequently grant access without adequate verification protocols.
Financial scale of extortion campaigns
Google’s analysis of Helix’s cryptocurrency wallets revealed the scale of the group’s extortion operation. Between January and May of this year, the gang accumulated at least $10.6 million in ransom payments from victim organizations. This figure represents only confirmed payments traced through blockchain analysis and likely understates the total haul, as some victims may have paid through channels harder to track or may have settled after the Google reporting period ended.

Part of a larger criminal ecosystem
Helix does not operate as a standalone entity but rather functions as part of UNC6671, a wider umbrella collective of hacking groups. This structure allows the criminals to distribute tasks, share access credentials, and coordinate campaigns across multiple organizations. The collective approach increases operational resilience—if one cell is disrupted, others can continue activity—and enables specialization among different teams within the network.
The grouping under UNC6671 indicates a level of organization that rivals some legitimate software companies in terms of scale and coordination. Multiple teams can be deployed against different targets simultaneously, and the shared infrastructure allows rapid intelligence sharing about vulnerability research, social engineering techniques, and target opportunities.
Implications for Uber and the logistics industry
While Uber Freight maintained that the breach caused no operational disruption, the incident raises questions about the security posture of cloud-dependent logistics operations. Uber Freight manages complex supply chains involving coordination between the company, customers, and drivers—all processes that rely on cloud infrastructure, email systems, and shared document repositories. The theft of accounts payable files and dispatch documents could potentially expose sensitive business logic or customer relationships to competitors.
The logistics sector has emerged as a particularly attractive target for extortion gangs because of the interconnected nature of supply chain operations. Unlike some industries where a data breach might be contained to internal systems, logistics companies operate within networks that span customers, vendors, and regulatory bodies. This creates multiple pressure points where an attacker can threaten exposure.
The broader context of transportation sector attacks
Helix’s targeting of Uber Freight is part of a sustained campaign against the transportation industry. Throughout 2026, the group has moved systematically through transportation companies, financial institutions, and private equity firms. This pattern suggests either that these sectors present particularly valuable targets due to the sensitivity of their data, or that they may have weaker security practices relative to other industries.
The transportation sector’s reliance on real-time systems and operational efficiency can sometimes conflict with security hardening. Companies in logistics prioritize uptime and responsiveness, which may lead to looser authentication protocols or faster credential provisioning than more security-conscious industries would allow.
Unanswered questions and next steps
Uber Freight has not clarified several critical details about the incident. The company has not specified when it discovered the breach, how long attackers had access to its systems, or what percentage of its data was compromised. It also has not addressed whether law enforcement was notified or whether any investigation into the attackers’ identity is underway.
The incident highlights the persistent challenge of defending against social engineering attacks. Technical defenses like firewalls and encryption can be bypassed when attackers manipulate human decision-making. Defense against voice phishing requires organizational culture changes—training support staff to verify identities through secondary channels, implementing strict protocols for credential resets, and using hardware security keys that cannot be reset via phone calls alone.
Frequently Asked Questions
What data did Helix claim to steal from Uber Freight?
Helix claimed to have taken mailboxes, cloud storage drives, files relating to accounts payable, and dispatch documents. The stolen files appeared to include email correspondence between Uber Freight and its customers, with some dated around mid-June.
How much money has Helix extorted from victims?
Google's analysis of Helix's cryptocurrency wallets showed the gang received at least $10.6 million in ransom payments between January and May 2026, making it one of the year's most profitable extortion operations.
What tactics does Helix use to breach company networks?
Helix primarily relies on social engineering, specifically voice phishing—attackers call corporate IT helpdesks impersonating employees and request password resets or other credential assistance to gain network access.