A hacking and extortion group says it broke into Uber Freight, the logistics arm of the ride-hailing giant, and walked away with a pile of sensitive files.
The company says its systems are still running and business is moving normally. But the claim raises fresh questions about how safe corporate data really is, especially for companies that handle shipping and supply chains.
What the Hackers Say They Took
Helix posted its claim on its data leak site, a common move for ransomware gangs that want to pressure victims into paying. The group says it grabbed email mailboxes, cloud storage drives, accounts payable files, and dispatch documents from Uber Freight.
TechCrunch reviewed files that seemed to display email correspondence linking Uber Freight to multiple customers. The files appeared to be dated around mid-June, but TechCrunch could not confirm whether they were authentic.
Uber Freight has not said whether the hackers contacted the company or whether any ransom was paid. The company also did not respond to TechCrunch's questions about the incident.
Get the free Always Be Buying eBook and learn the simple system for building wealth on any income
How This Group Operates
Helix has been busy this year, targeting shipping companies, financial institutions, and private equity firms. Its specialty is stealing large amounts of data from cloud environments and threatening to publish it unless victims pay up.
The group's methods are not exactly high-tech. The group leans on social engineering tricks like voice phishing, where attackers call IT helpdesks and ask for employee password resets.
Security experts have repeatedly warned that these tactics, while not sophisticated, work surprisingly well. A convincing phone call can be enough to get someone to hand over access to sensitive systems.
The approach appears to pay off. According to Google's blog post, a look at the gang's bitcoin wallets indicates it pocketed $10.6 million or more in extortion payments from January through May.
What This Means for Your Portfolio
For investors, this story is less about Uber specifically and more about the broader risk that comes with companies holding large amounts of customer and partner data. A breach at a logistics subsidiary does not necessarily hurt the parent company's bottom line, but it can create headaches around trust and reputation.
Uber Freight moves goods for businesses, which means it holds emails, dispatch records, and payment files that connect it to a web of corporate clients. If those files leak, the fallout could reach beyond Uber itself.
The good news is that Uber Freight says operations are unaffected, which suggests the breach did not disrupt the actual movement of goods. That matters, because a shutdown at a freight company can ripple through supply chains and hit consumers at the register.
The bigger takeaway is that cyberattacks are becoming a routine cost of doing business. Companies that handle sensitive data will keep getting tested, and how they respond will tell investors a lot about their long-term resilience.
Download the free Always Be Buying eBook and start putting your money to work today
