Full Report
Helix claims nearly a million files, while the logistics biz says operations never hit the brakes
Analysis Summary
# Incident Report: Uber Freight Data Security Incident
## Executive Summary
In August 2026, Uber Freight, the logistics arm of Uber, confirmed a data security incident following claims by the Helix extortion group. The attackers allegedly exfiltrated nearly one million files from cloud repositories, though the company maintains that its core logistics operations and business continuity remained unaffected.
## Incident Details
- **Discovery Date:** Approximately August 6, 2026 (based on leak site posting)
- **Incident Date:** July/August 2026
- **Affected Organization:** Uber Freight
- **Sector:** Logistics / Transportation
- **Geography:** North America
## Timeline of Events
### Initial Access
- **Date/Time:** July/August 2026
- **Vector:** Likely Vishing (Voice Phishing)
- **Details:** Based on researcher analysis of the threat actor (UNC6671), the attack likely began with operators posing as IT helpdesk staff to obtain credentials and authenticated sessions from employees via their personal phones.
### Lateral Movement
- **Details:** Attackers targeted identity infrastructure (Okta) and authenticated sessions to pivot into enterprise cloud environments.
### Data Exfiltration/Impact
- **Details:** The Helix group claimed to have accessed and stolen nearly one million files. The data reportedly originated from mailboxes, OneDrive accounts, and the accounts receivable department.
### Detection & Response
- **How it was discovered:** Detected internally (remediation cited) and confirmed publicly after Helix listed the company on its leak site on August 6, 2026.
- **Response actions taken:** Investigation launched, unauthorized access contained and remediated, and federal law enforcement notified.
## Attack Methodology
- **Initial Access:** Social Engineering (Vishing).
- **Persistence:** Authenticated sessions and potentially compromised identity provider (IdP) tokens.
- **Defense Evasion:** Use of multiple extortion brands (Helix, Pink, Redact) to compartmentalize operations and hide breach volumes.
- **Credential Access:** Phishing for credentials/MFA codes via phone-based social engineering.
- **Discovery:** Reconnaissance of cloud repositories and mailboxes.
- **Collection:** Siphoning data from Microsoft 365 services (OneDrive, Outlook).
- **Exfiltration:** Systematic theft of files from departmental repositories.
- **Impact:** Financial extortion and data leakage; however, no operational disruption was reported.
## Impact Assessment
- **Financial:** Potential extortion demands (amount undisclosed).
- **Data Breach:** Nearly 1 million files claimed stolen, including financial (accounts receivable) and internal communications.
- **Operational:** None; systems remained fully operational.
- **Reputational:** High-profile mention on a known extortion leak site.
## Indicators of Compromise
- **Network indicators:** Infrastructure shared with "BlackFile," "Pink," "Redact," and "Falcon" brands (UNC6671).
- **Behavioral indicators:** Unusual login activity from personal phone-based vishing attempts; unauthorized access to Okta/Microsoft 365 environments.
## Response Actions
- **Containment:** Blocked unauthorized access and secured repositories.
- **Eradication:** Remediated compromised accounts and identity infrastructure.
- **Recovery:** Confirmed systems are secure and fully operational; no disruption to shipping/logistics.
## Lessons Learned
- **Social Engineering Vulnerability:** Sophisticated vishing remains a highly effective bypass for traditional security controls, especially when targeting personal devices.
- **Identity Security:** The targeting of Okta and authenticated sessions highlights the need for robust, phishing-resistant MFA (such as FIDO2/WebAuthn).
## Recommendations
- **Employee Training:** Implement specific training for vishing, emphasizing that IT support will never request credentials or MFA codes via personal phone calls.
- **Harden Identity Providers:** Move toward hardware-based security keys to mitigate the risk of authenticated session theft.
- **Least Privilege:** Restrict access to large cloud repositories (OneDrive/SharePoint) to ensure that a single compromised account cannot access "nearly a million" files.