Skip to content
Leak-site post naming Uber, captured by ThreatCluster

Uber

helix

Ransomware leak-site victim intelligence

Posted
Aug 7, 2026
Countdown
00 Days 00 Hours 00 Mins 00 Secs
Country
US
Industry
Transportation

Summary

Written by ThreatClusterfrom victim profile, leak post, screenshot, our reporting

Helix states that Uber's Verified Open SharePoint libraries were taken and staged across four tiers (T1 to T4) on their leak, with tiers unlocking as countdown timers reach zero. The leak page states a countdown publication status, with T1 release expected first and later stages unlocking on schedule. The victim is Uber, and the leak lists SharePoint and OneDrive as platforms.

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

Victim profile

Platforms
SharePoint OneDrive

What was taken

Uber Verified Open board SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0.

Data categories
EmailsDocumentsDashboardsAttachments
File types seen
zip × 6
Sample files (6)
T1/Other_Small_Sites_T1/part-001.zip
T1/Mailbox_Emails/part-001.zip
T2/Other_Small_Sites_T2/part-001.zip
T3/Accounts_Payable_Dashboard_Documents/part-001.zip
T3/ROOT_Crossroads_Documents/part-001.zip
T3/Uber_Freight_Ops_Eng_Support_Documents/part-001.zip

Also stated on the leak page

Fields this group publishes that do not map to a standard column. Labels are the site's own.

label
Sensitivity layers
value
SharePoint libraries · T1 (least) → T4 (most). Stage packages unlock when each timer hits zero.
panel_status
All stages released
All stages released
true
Countdown until T1 releases; later stages unlock on schedule.
Countdown until T1 releases; later stages unlock on schedule.

Leak-site images (1)

Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.

ThreatCluster capture