Uber Freight keeps on trucking after extortion crew breaks in
Helix claims nearly a million files, while the logistics biz says operations never hit the brakes
Uber Freight, the logistics arm of ride-sharing giant Uber, is investigating a data security incident after the Helix extortion group listed the company's data leak on August 6. Helix claims to have stolen nearly 1 million files from various sources, including mailboxes, OneDrive accounts, and the accounts receivable department.
An Uber Freight spokesperson said the company was aware of the incident but that it had not yet disrupted daily operations. The company confirmed that a data security incident occurred, was contained, and remediated, with no impact on Uber Freight's business operations. Uber Freight manages 18 million shipments worth over $17 billion annually.
Helix, one of several recently established extortion brands, is linked to infrastructure associated with BlackFile, which retired its name in May. Experts believe Helix shares infrastructure with Pink, Redact, and Falcon brands, all of which are part of the UNC6671 cluster. Operators of UNC6671 often use vishing to gain an initial foothold and then employ device code phishing to obtain credentials and authenticated sessions.
They have been targeting organizations in the technology, transportation, and hospitality sectors, shifting from manufacturing, real estate, healthcare, and insurance. The reason for multiple extortion brands emerging after BlackFile's shutdown remains unclear, but experts speculate that it could be to compartmentalize operations, hide overall breach volumes, or isolate negotiation fallout.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Uber Freight keeps on trucking after extortion crew breaks in theregister.com