Uber Freight confirms cyber incident after hackers claim nearly 1 million files

Helix claims it accessed Uber Freight mailboxes, OneDrive and accounts-receivable materials.

An Uber Freight truck travels on a highway. The company confirmed a data-security incident involving unauthorized access to part of its systems and repositories. (Photo: FreightWaves)

A hacker group calling itself Helix claimed it stole nearly one million Uber Freight files. Uber Freight confirmed Wednesday that someone accessed part of its systems and repositories without permission. The company told FreightWaves it identified, contained and remediated the incident. It did not verify Helix’s files or identify the information involved.

Helix listed Uber Freight on its data-leak site Aug. 6 and described material from several repositories. The group claimed it accessed mailboxes, OneDrive accounts and accounts-receivable materials. It has not provided independent proof confirming the records’ authenticity or scope. Uber Freight has not confirmed the group’s description of the material.

Uber Freight confirms incident

An Uber Freight spokesperson told FreightWaves, “The incident was identified, contained and remediated.” The spokesperson added, “We promptly engaged federal law enforcement.” Uber Freight also wrote, “There has been no impact to Uber Freight’s business operations.” The company wrote, “Our systems are secure and fully operational.”

The response did not address whether customer, carrier, employee or vendor information appeared within accessed repositories. Uber Freight has not disclosed notifications, forensic assistance, or a timeline for further findings. The company also has not confirmed contact with Helix. Uber Freight continues to investigate the incident.

Google Threat Intelligence Group tracks Helix as part of the UNC6671 activity cluster. Researchers linked Helix, Falcon, Pink and Redact through shared phishing infrastructure. The group often impersonates corporate help desks through phone calls and fake login portals. Google does not identify Uber Freight as a confirmed UNC6671 victim.

Google reported that the cluster shifted toward transportation, technology and hospitality targets during June. Its researchers documented campaigns designed to capture employee credentials and multi-factor authentication tokens. Those credentials can allow criminals to access cloud tools and remove company information. Uber Freight has not identified how someone accessed its systems.

Why it matters

Freight platforms can hold shipping, carrier, payment and pricing data that criminals may target after unauthorized access. Uber Freight confirmed the incident, but the company has not disclosed what information the intruder accessed.

CFCO

FreightWaves offers Certified Fraud Compliance Officer coursework for transportation professionals. The program includes practical lessons on identity verification, suspicious communications and fraud-response decisions. Google reported that Helix-linked actors pose as help-desk personnel to capture credentials. Those verification steps can help teams identify a scam before granting system access.

Click here for more articles on cargo theft and freight fraud by Phil Brink.

K9 stop on Louisiana’s I-12 uncovers 358 kilos of meth in semi-trailer, driver now in ICE custody – FreightWaves

Wild West returns to California rails as suspected train burglar fires at BNSF officer – FreightWaves

Prosecutors say a hit man killed a federal witness tied to staged 18-wheeler crashes – FreightWaves

Upcoming FreightWaves Events
Compliance

Brokerage Compliance Symposium

The day before F3. Every compliance issue you face - fraud exposure, carrier liability, FMCSA rules, cargo theft, insurance gaps - navigated by attorneys and operators defining best practices in a changing industry.

October 26, 2026
The Signal at Chattanooga Choo Choo • Chattanooga, TN
Register Now
Awards

F3 Awards Dinner

The night before F3. FreightTech100 companies honored. FreightTech 25 and Shipper of Choice winners revealed live. Cocktail reception into dinner and live music - 300 industry leaders in one purpose-built room.

October 26, 2026
The Signal at Chattanooga Choo Choo • Chattanooga, TN
Register Now
FreightTech

F3: Future of Freight Festival

Industry-defining keynotes, rapid-fire technology demos, and industry leaders networking in experiences across Chattanooga - plus the inaugural F3 Awards Dinner featuring the FreightTech and Shipper of Choice reveals.

October 27, 2026 – October 28, 2026
The Signal at Chattanooga Choo Choo • Chattanooga, TN
Register Now
Compliance Brokerage Compliance Symposium Oct 26 • The Signal at Chattanooga Choo Choo • Chattanooga, TN

The day before F3. Every compliance issue you face - fraud exposure, carrier liability, FMCSA rules, cargo theft, insurance gaps - navigated by attorneys and operators defining best practices in a changing industry.

The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now
Awards F3 Awards Dinner Oct 26 • The Signal at Chattanooga Choo Choo • Chattanooga, TN

The night before F3. FreightTech100 companies honored. FreightTech 25 and Shipper of Choice winners revealed live. Cocktail reception into dinner and live music - 300 industry leaders in one purpose-built room.

The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now
FreightTech F3: Future of Freight Festival Oct 27 – Oct 28 • The Signal at Chattanooga Choo Choo • Chattanooga, TN

Industry-defining keynotes, rapid-fire technology demos, and industry leaders networking in experiences across Chattanooga - plus the inaugural F3 Awards Dinner featuring the FreightTech and Shipper of Choice reveals.

The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now

Phil Brink

Phil Brink is the Head of Fraud Media and Education at FreightWaves, where he investigates cargo theft, freight fraud and transportation security. He owned and operated a freight brokerage for more than a decade before organized fraud targeted his business, forcing him to rethink how freight companies identify and manage risk. The lessons he learned continue to shape his reporting, education and collaboration with brokers, carriers, shippers and law enforcement. He developed FreightWaves' Certified Fraud Compliance Officer (CFCO) program to give transportation professionals practical knowledge and a structured framework for identifying and managing fraud risk. Reach him at phil.brink@firecrown.com.