Uber Freight reportedly investigating after hacking group claims data breach
I'll pull the TechCrunch report and the post-writing rules so the paragraphs stay factual and match the house style.The summary is thin, so I’m reading the…
By Dillip Chowdary • Aug 14, 2026 • Source: TechCrunch
What happened
I'll pull the TechCrunch report and the post-writing rules so the paragraphs stay factual and match the house style.The summary is thin, so I’m reading the TechCrunch piece and the Reuters report it cites before writing — no invented counts or dates.Uber Freight, the logistics subsidiary of Uber, is investigating after a hacking and extortion gang took credit for a cyberattack and data breach at the company, TechCrunch reported. Reuters first published the incident. A spokesperson for Uber Freight told Reuters there was no effect on business operations and that its systems were running normally. Uber Freight did not immediately respond to questions from TechCrunch. The group, identified by TechCrunch as Helix, is known for targeting transportation companies, financial giants, and private equity firms, and it posted the Uber Freight claim on the data leak site it uses to host stolen files. Uber Freight has not said whether it received correspondence from the hackers or whether it paid a ransom.
Helix's published method is cloud theft plus a deadline, not a warehouse outage. TechCrunch reports that the group exfiltrates large amounts of data from cloud environments and threatens to publish the files if the victim does not pay. On the leak site, Helix claims it took mailboxes, cloud storage drives, files relating to accounts payable, and dispatch documents from Uber Freight. Some files seen by TechCrunch appear to show email correspondence between Uber Freight and several of its customers. TechCrunch could not immediately verify that those files are authentic. The ones it reviewed appeared dated around mid-June. Google said Helix is part of a wider umbrella it tracks as UNC6671 and that the gang relies on social engineering, including voice phishing in which operators call IT helpdesks and request employee password resets. That path does not need a freight-platform exploit. It needs a helpdesk that will mint a new credential, after which mailbox, drive, payables, and dispatch shares in the same tenant become one session.
The technical detail

For engineers building identity, TMS, broker tools, or any SaaS that stores invoices next to operational documents, the claim is a blast-radius diagram. Mailboxes hold rate confirmations and customer threads. Cloud drives hold the attachments those threads reference. Accounts payable files hold vendor identifiers and payment schedules. Dispatch documents hold lanes, appointments, and consignees. If a single reset identity can read all four, the control that failed is not the load board. It is helpdesk password reset, MFA reset, and OAuth consent treated as low-privilege ticket work. Builders should put step-up verification and auditable logging on those actions, separate finance and dispatch roles from general mailbox tokens, and assume a mailbox compromise includes every drive scope that token already holds.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
Why it matters for builders
The market context is the victim set, not a new freight product. Helix has spent the year on transportation companies, financial firms, and private equity shops, which is one graph: shippers, brokers, lenders, and the sponsors who own logistics portfolios. Digital freight networks concentrate exactly the files named in the listing, which is why a broker brand is a better extortion target than a single carrier with a small email domain. Uber Freight's competitors in digital brokerage and managed transportation sit on similar cloud tenants and similar payables-plus-dispatch stores. Google said a review of the gang's bitcoin wallets shows at least 10.6 million dollars in ransom payments between January and May this year. That figure is not a loss attributed to Uber Freight. It is the reason a leak-site listing of a transportation company is a business process.
Market and competitive context
What to watch is confirmation, scope, and notification, not uptime. Uber Freight has already said operations were unaffected. Confidentiality is a different claim, and the company has not said the sample emails are real, which customers appear in them, or whether a ransom note arrived. If the mid-June dating TechCrunch observed holds, there is a weeks-long window in which anomalous helpdesk resets, new OAuth grants, and bulk cloud-drive downloads would still be the right forensic objects. Watch for a statement that names the identity system and the repositories, a customer-notification plan for anyone in the correspondence, and a written line that parent Uber rider and driver systems are out of scope. Watch whether Helix adds files or a countdown. Treat the Reuters operations line as a statement about matching and dispatch continuity, not about whether payables archives are sitting on a leak site.
What to watch next
Several points remain open, and they should stay open until Uber Freight or a regulator closes them. TechCrunch could not verify the files it saw. Helix's inventory of mailboxes, cloud storage, accounts payable material, and dispatch documents is still an unverified claim. Google's UNC6671 voice-phishing writeup describes the gang's known tactics, not a confirmed entry path for this incident. Uber Freight has not said it was contacted or that it paid. Unanswered questions include which identity provider was involved, whether a helpdesk reset occurred here, how many customers are in the threads, and whether any access crossed from Freight into parent Uber systems. Related prior art at Uber is social engineering of employees and delayed handling of stolen data, including the 2022 internal-network incident and the 2016 rider and driver breach, not a documented Freight-specific malware family. Those cases do not prove this one. They are why a statement that trucks are still moving is not a substitute for a statement about email and payables.
Advertisement
🔎 More interesting news
- Google announces Gemini 3.7 Flash just three weeks after previous release
- SpaceXAI debuts Grok 4.6, overtaking Kimi K3's performance and matching GPT-5.6 Sol for…
- Writer introduces new AI model and upgraded harness to contain token costs
- ChatGPT for Mac adds opt-in Computer History feature, replacing Chronicle
- Today's full Tech Pulse briefing →