Thenextweb Uber Freight Investigates Major Data Breach by Helix Hacking Group
Article Content
- •Helix hacking group claims to have stolen nearly 1 million files from Uber Freight.
- •The breach was announced on August 6, 2026, with no reported impact on business operations.
- •Google GTIG links Helix to a broader extortion campaign involving multiple hacking brands.
Uber Freight is currently investigating a significant data security incident after the Helix hacking group claimed to have stolen nearly one million files from its systems. The breach was announced on August 6, 2026, with Helix posting the alleged stolen data on its dark web site. Uber Freight has stated that there has been no impact on its business operations, and its systems remain secure and operational. The attack method involved unauthorized access to mailboxes and cloud storage, with the group using social engineering tactics such as voice phishing (vishing) to gain initial access. Google Threat Intelligence Group (GTIG) has linked Helix to a broader cluster of cyber extortion activities under the designation UNC6671, which includes other brands like Pink, Redact, and Falcon. The group has targeted various high-value sectors, including technology and transportation, and has reportedly received significant ransom payments in the past. Federal law enforcement has been engaged in the investigation, and Uber Freight has stated that the incident has been contained and remediated.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Following this threat?
Track Pink and Apollo Global Management in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Vishing Attacks Target Executives for Microsoft 365 Data Theft A wave of data theft and extortion targeting Microsoft 365 and other SaaS accounts has emerged, tracked by Arctic Wolf as PREY-0058. The attackers use vishing calls impersonating IT help desk staff to trick executives into providing credentials and multi-factor authentication (MFA) approvals. This method involves…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…