Uber Freight cyber incident under investigation after Helix file claim
Uber Freight says unauthorized access was contained and freight operations continue, while Helix’s claim of nearly 1 million files remains unverified.
By Dominic Okoye · Staff Writer
· 3 min read
Uber Freight says it is investigating an unauthorized-access event affecting part of its systems and repositories. The Uber Freight cyber incident was identified, contained and remediated, the company said, and it reported no interruption to day-to-day freight operations.
The company said it promptly involved federal law enforcement. It did not put a number on the affected systems or repositories. Uber Freight also said its systems were secure and fully operational, a statement about service availability rather than verification of Helix’s separate claims about data theft.
What happened in the Uber Freight cyber incident?
Helix, an extortion group, published a post on its site on August 6 claiming it held nearly 1 million Uber Freight files, Reuters reported. The Register said the group asserted that the material came from mailboxes, OneDrive accounts, accounts receivable and other repositories.
Those assertions have not been verified. An Uber Freight spokesperson did not comment on whether the purported files were authentic, when the company learned of the breach, or whether it had interacted with Helix, according to Reuters. The Register said it did not download the staged releases, and reported that Uber Freight neither confirmed nor denied their authenticity.
For customers, carriers and shippers using the platform, the distinction is material: a company can restore or maintain operational systems while questions about data claimed by an outside group remain unresolved. Uber Freight’s own privacy notice says its services handle categories that include account and payment information, location data, load records, communications and device data. That notice does not establish that any particular category was accessed in this incident.
What is known and what remains unverified
Confirmed by Uber Freight: unauthorized access involved a portion of its systems and repositories; the company says it contained and remediated the incident, engaged federal law enforcement, and has continued operations without disruption.
Claimed by Helix: it obtained nearly 1 million files. The claimed origins of some material, including corporate mailboxes and OneDrive, are also Helix’s allegation.
Not addressed by the company: whether the alleged files are genuine, when Uber Freight became aware of the incident, and whether it interacted with Helix.
Reuters reported that Google Threat Intelligence has associated Helix with a wider cluster of high-profile hacking activity. The Register reported Google tracks that activity as UNC6671 and has described voice phishing and device-code phishing as methods used by operators in the cluster. Neither report establishes that those techniques were used against Uber Freight.
Uber Freight’s public Trust Center describes controls such as monitoring, vulnerability scanning, network segmentation and access reviews. Such disclosures outline the company’s stated enterprise security program; they do not explain how this unauthorized access occurred or whether any control failed.
The immediate operational consequence appears limited on Uber Freight’s account. The central unresolved issue is whether Helix’s alleged file cache is genuine, and, if so, what it contains.
This story draws on original reporting from The Register.