Uber Freight is investigating a data security incident days after the Helix extortion group listed the logistics company on its leak site and claimed to have stolen nearly 1 million files.
Helix said the haul came from mailboxes, OneDrive accounts, the accounts receivable department, and other repositories. An Uber Freight spokesperson told The Register the incident was identified, contained, and remediated, that federal law enforcement was engaged, and that business operations continued without disruption.
Uber Freight is the ride-hailing company’s logistics arm, describing itself as one of North America’s largest managed transportation networks, handling 18 million shipments carrying more than $17B in goods each year. It neither confirmed nor denied that the released material was authentic.
Helix is one of several recently established extortion brands that researchers link to infrastructure associated with BlackFile, which retired its name in May. According to Google Threat Intelligence Group, Helix shares infrastructure with the Pink, Redact, and Falcon brands, tracked collectively as UNC6671.
Operators in the cluster often gain an initial foothold through vishing, posing as IT helpdesk staff overseeing mandatory security migrations. They contact employees on personal phones and use device code phishing to obtain credentials and authenticated sessions before siphoning data from cloud services like Microsoft 365. They have also targeted Okta identity infrastructure.
Since June, the UNC6671-linked brands have favored technology, transportation, and hospitality targets after focusing on manufacturing, real estate, healthcare, and insurance during April and May. Google said the multi-brand strategy could compartmentalize operations, hide overall breach volumes, and isolate negotiation fallout.
For defenders, the campaign is a reminder that vishing plus device code phishing can defeat MFA. Employees should verify any unsolicited helpdesk contact on a separate, trusted channel.
