Google ties the Uber Freight hackers to a $10.6 million vishing operation

Source Cryptopolitan

The extortion gang Helix claims to have hacked Uber Freight, the logistics arm of the ride-hailing company.

They have begun leaking what they assert to be around one million stolen files. Uber Freight says the intrusion did not disrupt business.

Uber Freight confirms a breach but won’t discuss ransom

Uber Freight appeared on Helix’s data leak site on August 6, the date on which the gang began listing the company.

A few days later, the firm said it was investigating what it called a data security incident.

“We are investigating a data security incident involving unauthorized access to a portion of Uber Freight’s systems and repositories. The incident was identified, contained, and remediated, and we promptly engaged federal law enforcement,” the company said, adding that its systems were “secure and fully operational” with no impact on operations.

The company has not said whether it heard from the hackers at all or if any ransom changed hands.

Helix’s own tally runs to about a million files pulled from mailboxes, OneDrive accounts, the accounts receivable department, and other internal repositories. The leak listing adds accounts payable records and dispatch paperwork to that inventory.

Some of the documents appeared to be email exchanges between Uber Freight and its customers, with timestamps clustered around mid-June. The files could not be verified, and Uber Freight would not confirm or deny them.

Uber Freight says it is one of the largest managed-transportation networks in North America. It says it moves over $17 billion of goods in 18 million shipments each year.

Google ties Helix to a $10.6 million extortion crew

Google’s Threat Intelligence Group has linked Helix to a cluster it calls UNC6671, the same operation that also runs under the Redact, Pink, and Falcon banners. Google connects that group back to BlackFile, a brand retired in May 2026.

The intrusion method has been consistent across those labels. Operators call employees, often on personal mobiles, and impersonate IT helpdesk staff pushing an urgent, mandatory security migration, Google wrote in its August 7 report.

The calls lead targets to fake login pages where adversary-in-the-middle tooling collects passwords and multi-factor tokens, allowing access to cloud data in Microsoft 365 and Okta.

Google said an analysis of the group’s bitcoin wallets found at least $10.6 million was collected in ransoms from January to May. The crew has been targeting technology, transportation, and hospitality victims since June, veering away from the manufacturing, healthcare, and insurance targets it was working on earlier in the spring.

Cryptopolitan reported vishing attempts targeted Wall Street funds such as Point72, Citadel, Two Sigma, and Millennium this month, though the firms said client data remained secure.

In February, blockchain lender Figure Technology confirmed a breach after an employee was talked into granting file access. The breach was part of a campaign targeting companies that use Okta single sign-on, the same identity layer that UNC6671 targets.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Forex Today: US Dollar stabilizes ahead of next batch of US dataHere is what you need to know on Thursday, August 13:
Author  FXStreet
13 hours ago
Here is what you need to know on Thursday, August 13:
placeholder
WTI declines below $82.50 as oil inventories rise far more than expectedWest Texas Intermediate (WTI), the US crude oil benchmark, is trading around $82.45 during the early Asian trading hours on Thursday. WTI declines on a larger-than-expected build in US crude oil inventories. Traders will closely monitor the developments surrounding US-Iran talks for fresh impetus. 
Author  FXStreet
21 hours ago
West Texas Intermediate (WTI), the US crude oil benchmark, is trading around $82.45 during the early Asian trading hours on Thursday. WTI declines on a larger-than-expected build in US crude oil inventories. Traders will closely monitor the developments surrounding US-Iran talks for fresh impetus. 
placeholder
Gold Price Forecast: Can Gold Keep Rising After Reclaiming $4,400 as Markets Await Upcoming CPI Data?During Wednesday's Asian trading session, spot gold (XAUUSD) extended its rebound, reclaiming $4,400/oz. As of 11:08 Beijing time on August 12, spot gold was trading at $4,414.705/oz, up
Author  TradingKey
Yesterday 10: 15
During Wednesday's Asian trading session, spot gold (XAUUSD) extended its rebound, reclaiming $4,400/oz. As of 11:08 Beijing time on August 12, spot gold was trading at $4,414.705/oz, up
placeholder
WTI advances above $82.50 due to mixed signals regarding potential US-Iran dealWest Texas Intermediate (WTI) oil price extends its gains for the third successive day, trading around $82.70 per barrel during the Asian hours on Wednesday. Crude oil prices advance as investors weigh mixed signals regarding a potential deal between the United States (US) and Iran.
Author  FXStreet
Yesterday 01: 16
West Texas Intermediate (WTI) oil price extends its gains for the third successive day, trading around $82.70 per barrel during the Asian hours on Wednesday. Crude oil prices advance as investors weigh mixed signals regarding a potential deal between the United States (US) and Iran.
placeholder
Gold Price Forecast: Cooling Rate Hike Expectations Push Gold Above $4,400, Eyeing $4,500 Next As of the European session on August 11, gold prices (XAUUSD) briefly topped $4,400 intraday, reaching a high of $4,435.2, its highest level since June 5. However, gains subsequently narr
Author  TradingKey
Aug 11, Tue
As of the European session on August 11, gold prices (XAUUSD) briefly topped $4,400 intraday, reaching a high of $4,435.2, its highest level since June 5. However, gains subsequently narr
goTop
quote