Uber Freight is investigating a significant data security incident after the Helix extortion crew claimed responsibility for breaching its systems and stealing close to one million files. The attack, which specifically targeted Microsoft 365 and Okta infrastructure, exemplifies the evolving tactics used by threat actors against major logistics and transportation companies.
Helix Extortion Crew Targets Uber Freight Systems
On 6 August 2026, the Helix extortion group listed Uber Freight on its data leak site, boasting of a successful breach. Helix claims to have exfiltrated nearly one million files from various company sources, including employee mailboxes, OneDrive accounts and repositories associated with the accounts receivable department. While Uber Freight has not confirmed the authenticity of the stolen data, the company acknowledged the incident and engaged federal law enforcement to investigate.
Uber Freight, a subsidiary of the well-known ride-sharing company Uber, operates one of North America’s largest managed transportation and multimodal capacity networks. The company manages millions of shipments annually, with goods valued at over 17 billion US dollars. Despite the breach, Uber Freight stated that its business operations remain unaffected and that systems are “secure and fully operational.”
Attack Techniques: Vishing and Device Code Phishing
Researchers have linked Helix to a broader cluster of cybercriminal activity tracked as UNC6671. This group employs sophisticated social engineering tactics, including vishing and device code phishing, to gain unauthorised access to cloud-based services. According to Google Threat Intelligence Group (GTIG), operators impersonate IT helpdesk staff, contacting targeted employees via their personal phones. They claim to oversee mandatory security migrations, convincing victims to divulge credentials or approve authentication requests.
Once initial access is achieved, attackers leverage device code phishing to hijack authenticated sessions. This enables them to bypass typical multi-factor authentication protections and access cloud services such as Microsoft 365 and Okta. After obtaining credentials, attackers move laterally within the environment, ultimately exfiltrating sensitive files and data from mailboxes and cloud storage repositories.
- Initial access via vishing: Attackers call employees, posing as IT staff.
- Device code phishing: Victims are tricked into providing authentication codes or session approvals.
- Credential harvesting: Attackers steal logins for Microsoft 365 and Okta accounts.
- Data exfiltration: Large volumes of files are copied from cloud repositories.
The Helix operation is not isolated. GTIG notes that Helix shares infrastructure with other extortion brands, including Pink, Redact and Falcon, all emerging after the apparent retirement of the BlackFile brand in May. The shared infrastructure and tactics suggest these groups are part of a coordinated threat actor ecosystem.
Timeline and Impact of the Uber Freight Attack
The timeline of the Uber Freight incident highlights both the speed and scale of modern cyber extortion attacks:
- May 2026: BlackFile retires its brand, prompting the emergence of Helix and other linked groups.
- April-May 2026: UNC6671 activity focuses on manufacturing, real estate, healthcare and insurance sectors.
- June 2026 onwards: Shift in targeting to higher-value sectors, including technology, transportation and hospitality.
- 6 August 2026: Helix lists Uber Freight as a victim on its data leak site, claiming theft of nearly one million files.
- August 2026: Uber Freight confirms an ongoing investigation, containment and remediation, with no operational disruption.
While Uber Freight has neither confirmed nor denied the authenticity of the leaked data, the Helix group has reportedly released portions of the stolen files in stages. This is a common tactic among ransomware and extortion groups to pressure victims into negotiation or payment. The precise nature of the stolen files remains undisclosed, but the inclusion of mailboxes, OneDrive accounts and finance department repositories suggests a risk to sensitive operational and financial data.
Broader Trends: Extortion Group Fragmentation and Targeting
The Uber Freight incident is part of a larger trend involving the fragmentation and evolution of cyber extortion groups. According to GTIG, the dissolution of BlackFile has resulted in the emergence of several new brands sharing infrastructure and tactics. The reasons for this fragmentation may include:
- Compartmentalising operations to obscure overall breach volumes
- Isolating negotiation fallout to individual brands
- Managing internal disagreements over finances and operational security
- Outsourcing parts of the extortion process while retaining control over intrusions
- Utilising the same phishing toolkits across multiple groups
This approach complicates incident response and attribution for defenders. The shift in targeting towards higher-value sectors, such as transportation and technology, further increases the stakes for organisations that depend on cloud-based identity and collaboration services, especially Microsoft 365 and Okta.
Why This Data Breach Matters
The Uber Freight breach underscores the persistent threat posed by extortion groups using advanced social engineering and phishing tactics to bypass cloud security controls. The volume of data reportedly stolen, combined with the targeting of critical business infrastructure, highlights the ongoing risk for organisations relying on cloud providers for identity management and collaboration. The incident demonstrates how attackers can rapidly adapt to organisational and sectoral changes, making effective incident response and user awareness essential.
What Organisations Should Do
Organisations using Microsoft 365, Okta or other cloud identity services should:
- Review and update access controls and authentication policies regularly
- Educate users on vishing and phishing tactics targeting cloud accounts
- Monitor for unusual authentication activity and promptly investigate alerts
- Implement strong incident response plans tailored to cloud environments
As attackers increasingly target cloud-based infrastructure, organisations must remain vigilant against evolving social engineering threats.
Originally reported by www.theregister.com.






