Published Invest3 min read
Uber Freight's breach did not come through software. It came through a phone call.
Helix listed the logistics arm on August 6 and started leaking what it claims is a million files. Google says the same crew collected at least $10.6 million in five months by impersonating IT help desks.
Context for builders, not their beat.See today for builders

What happened
- The extortion gang Helix listed Uber Freight on its data leak site on August 6, the date the gang began listing the company.
- Helix claims about one million stolen files and began leaking what it asserts to be that material.
- Helix's own tally runs to about a million files pulled from mailboxes, OneDrive accounts, the accounts receivable department, and other internal repositories.
- Uber Freight said: "We are investigating a data security incident involving unauthorized access to a portion of Uber Freight's systems and repositories. The incident was identified, contained, and remediated, and we promptly engaged federal law enforcement."
- Uber Freight said its systems were "secure and fully operational" with no impact on operations, and that the intrusion did not disrupt business.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
The extortion gang Helix listed Uber Freight on its data leak site on August 6 and began publishing what it claims are roughly a million files taken from mailboxes, OneDrive accounts, the accounts receivable department and other internal repositories [1][2][3]. Uber Freight says it identified, contained and remediated a data security incident and that its systems remain "secure and fully operational" with no impact on operations [4][5], which leaves the operator question intact: the access route Google describes for this crew is a telephone, not a vulnerability.
Google's Threat Intelligence Group, in an August 7 report, tied Helix to a cluster it tracks as UNC6671, which has also operated under the Redact, Pink and Falcon names, and which Google connects back to a retired brand called BlackFile [6][7]. The method has not changed across the rebrands. Operators call employees, often on personal mobile numbers, pose as IT help desk staff and push an urgent, mandatory security migration [8]. The call steers the target to a fake login page where adversary-in-the-middle tooling harvests the password and the multi-factor token, which is enough to reach cloud data in Microsoft 365 and Okta [9].
That works, and Google has the receipts. An analysis of the group's bitcoin wallets found at least $10.6 million in ransoms collected from January to May [10], an average of about $2.1 million a month [11]. Since June the crew has been working technology, transportation and hospitality targets, after spending the spring on manufacturing, healthcare and insurance [12]. Cryptopolitan reported that vishing attempts this month reached Wall Street funds including Point72, Citadel, Two Sigma and Millennium, all of which said client data remained secure [13]. In February, blockchain lender Figure Technology confirmed a breach after an employee was talked into granting file access, part of a campaign against companies using Okta single sign-on [14].
The composition of the claimed Uber Freight haul is what should concern counterparties rather than the headline file count. Helix's listing adds accounts payable records and dispatch paperwork to the inventory [15], and some documents appeared to be email threads between Uber Freight and its customers with timestamps clustered around mid-June [16]. The files could not be verified, and Uber Freight would not confirm or deny them [17]. Uber Freight describes itself as one of the largest managed-transportation networks in North America, moving more than $17 billion of goods across 18 million shipments a year [18], which works out to roughly $944 of freight per shipment [19]. Payables, receivables and dispatch documents at that volume are exactly the raw material for convincing invoice redirection against shippers and carriers who were never breached themselves.
Uber Freight has not said whether the attackers contacted it or whether any money moved [20]. Watch three things: whether Helix publishes beyond the sample, whether Uber Freight's customers start reporting payment-diversion attempts referencing real load numbers, and whether logistics peers respond by hardening help-desk identity checks and moving to phishing-resistant authentication. The last one is the only defense that addresses what Google actually described.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The extortion gang Helix listed Uber Freight on its data leak site on August 6, the date the gang began listing the company.
ReportedView cited source - [2]
Helix claims about one million stolen files and began leaking what it asserts to be that material.
ReportedView cited source - [3]
Helix's own tally runs to about a million files pulled from mailboxes, OneDrive accounts, the accounts receivable department, and other internal repositories.
ReportedView cited source - [4]
Uber Freight said: "We are investigating a data security incident involving unauthorized access to a portion of Uber Freight's systems and repositories. The incident was identified, contained, and remediated, and we promptly engaged federal law enforcement."
- [5]
Uber Freight said its systems were "secure and fully operational" with no impact on operations, and that the intrusion did not disrupt business.
- [6]
Google's Threat Intelligence Group has linked Helix to a cluster it calls UNC6671, the same operation that also runs under the Redact, Pink, and Falcon banners.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cryptopolitan.comRanda MosesAug 13Google ties the Uber Freight hackers to a $10.6 million vishing operation
Additional citations
- Uber Freight statement quoted by Cryptopolitan
- Uber Freight
- Google Threat Intelligence Group
- Google Threat Intelligence Group, August 7 report
- Cryptopolitan



