Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Uber Freight Confirms Cyber Incident: What the Helix Breach Claim Means for Freight, Logistics, and Vendor Security

August 17, 2026

Uber Freight’s global headquarters sits inside Chicago’s Old Main Post Office, where Uber leases roughly 450,000 square feet and has based about 2,000 employees since the office opened in 2021. It’s one of the largest logistics operations run out of this city. This week, it’s also at the center of one of the bigger breach claims in freight.

On August 6, 2026, a hacking and extortion group calling itself “Helix” listed Uber Freight on its data-leak site, claiming to have taken nearly 1 million files. Uber Freight confirmed a cybersecurity incident involving unauthorized access to a portion of its systems days later. TechCrunch and The Register both reported the confirmation on August 12; FreightWaves followed on August 13.

If you run a freight brokerage, a carrier, a 3PL, or any business that depends on a TMS, a dispatch system, or an AP/AR pipeline to move freight and get paid, this is worth five minutes of your attention.

Here’s what’s actually known, what isn’t, and what it means for your own systems, separate from the freight-fraud story we’ve covered before, because this is a genuinely different kind of attack.

What Happened

DateEvent
August 6, 2026Helix posts Uber Freight to its data-leak site, claiming nearly 1 million files taken.
August 11–13, 2026Uber Freight publicly confirms and addresses the incident.

“The incident was identified, contained, and remediated, and we promptly engaged federal law enforcement. There has been no impact to Uber Freight’s business operations, which continue in the normal course without disruption.” (Uber Freight, official statement)

Who’s behind it: Google’s threat researchers track Helix as part of a broader activity cluster the company labels UNC6671, a set of related extortion crews that also includes groups Google calls Falcon, Pink, and Redact.

Icon grid of the five categories of data Helix claims to have taken from Uber Freight.

What Helix claims to have taken (its own listing, not independently verified by Uber Freight):

  • Email mailboxes
  • Cloud storage and OneDrive accounts
  • Accounts payable and accounts receivable files
  • Dispatch documents

Separately, TechCrunch reported that files it reviewed appeared to show email correspondence between Uber Freight and several of its customers, dated around mid-June, though it could not verify the files’ authenticity.

What’s Confirmed vs. What Isn’t

This is where a lot of breach coverage gets sloppy, so we’re going to be precise instead.

ConfirmedNot Confirmed
Uber Freight had a cybersecurity incident involving unauthorized access to a portion of its systems and repositories.The “nearly 1 million files” number is Helix’s own claim on its leak site; Uber Freight has not verified that figure.
The company says it identified, contained, and remediated the incident.What data was actually accessed.
Uber Freight engaged federal law enforcement.Whether customer, carrier, employee, or vendor data was involved.
Business operations have continued without disruption.Whether a ransom was demanded, or paid; no source has confirmed either way, and we’re not asserting one.

Also not confirmed: the exact technique used against Uber Freight. What’s documented is the broader UNC6671 cluster’s general playbook, per Google’s research: voice phishing (“vishing”) calls and fake login portals designed to trick employees into handing over credentials and MFA tokens, which attackers then use to get into cloud systems. Security researchers have long warned that the technique is crude but highly effective at getting a person to hand over access.

The cluster’s broader campaign collected at least $10.6 million in ransom payments between January and May 2026, per Google’s analysis. That figure describes UNC6671’s overall activity, not this specific incident; we’re not implying otherwise.

That gap between what an extortion group claims and what a company has actually confirmed matters, and it cuts both ways. Groups like Helix have every incentive to inflate a claim: a bigger number makes for a bigger headline and more pressure to pay.

But “we haven’t confirmed exactly what was taken yet” isn’t the same as “nothing was taken.” If your business exchanges dispatch paperwork, invoices, or email correspondence with Uber Freight, that unresolved question is worth watching, not dismissing.

Why This Matters If You’re in Freight, Logistics, or Trucking

Set aside for a moment whether Uber Freight’s own data was fully compromised. Look instead at what Helix says it went after, because that list is a blueprint for the systems every logistics operation runs on: email, cloud storage, accounts payable, accounts receivable, and dispatch documents.

That’s not a random grab bag. It’s the exact stack that keeps freight moving and money flowing:

  • The TMS that assigns loads
  • The dispatch system that tracks pickups and deliveries
  • The AP/AR process that pays carriers and collects from shippers

If an attacker gets into any one of those, they don’t just see data; they can potentially intercept payment instructions, impersonate a real load, or use compromised email threads to redirect a wire. Every dollar that moves through a logistics operation moves through systems that look exactly like what Helix claims it took from Uber Freight.

This is also where the vishing angle matters, even though it’s not confirmed as the specific method used here. Dispatchers and back-office staff take a high volume of phone calls from people claiming to be carriers, brokers, drivers, or IT support, which makes freight operations a genuinely attractive target for a caller impersonating IT and asking someone to “verify their login” over the phone.

The FBI has separately documented cyber-enabled load-board fraud escalating sharply (more on that below), and a voice-phishing crew targeting the same industry from a different angle is not a coincidence worth ignoring.

If you don’t currently have a clear answer to “what would happen if someone called our dispatch or billing team pretending to be IT and asked for a login,” that’s the gap worth closing first. LeadingIT built the NMFTA Cybersecurity Risk Check specifically to answer that question for trucking and logistics operations. It looks at exactly the systems in play here: dispatch, billing, and your TMS.

Why This Matters Even If You’ve Never Shipped a Pallet

You don’t have to be in freight for this story to be relevant. Uber Freight is, functionally, a vendor and counterparty to a large number of shippers, carriers, and partner companies, and this is the same shape of risk every business takes on the moment it connects its email, its payment process, or its data to a third party.

If Helix’s claims hold up even partially, the exposure isn’t just Uber Freight’s. It’s every carrier and customer whose emails, invoices, or dispatch paperwork sat in the systems Helix says it accessed.

That’s the uncomfortable truth about vendor risk: your security posture is only as strong as the weakest link in every company you do business with, and you often don’t find out where that weak link was until after the fact.

Two practical questions worth asking this week:

  • Do you know which of your vendors handle your payment or dispatch data, and have you ever asked how they protect it?
  • If a vendor you rely on were breached tomorrow, would you have any way of knowing whether your own credentials or data showed up in the leak?

LeadingIT’s dark web exposure check answers the second question directly: it tells you whether your company’s data is already circulating where attackers buy and sell it. Our guide on third-party vendor security walks through the first one in more depth.

The Bigger Pattern: Freight Is Having a Rough Year

The Uber Freight incident doesn’t exist in a vacuum. It lands in the middle of a genuinely bad stretch for freight-industry fraud and theft, and the numbers back that up from multiple independent sources.

By the Numbers: Freight Fraud & Cargo Theft, 2025–2026

CargoNet’s Q2 2026 report is the most current read on where freight theft and fraud actually stand, and the shape of it is not what most people expect.

MetricFigure
Reported cargo-theft/fraud losses (Q2 2026)$304.6 million
Same quarter last year (Q2 2025)$135.7 million (more than double)
Total theft reports, US + Canada677 (down 26% year-over-year, down 14% quarter-over-quarter)
Average value of a stolen shipment$564,009 (up sharply)
Fictitious-pickup incidents158
BEC / misdirection fraudDescribed as “steady”

Fewer incidents, but each one costs far more. That’s the story inside these numbers.

As Scott Cornell, chair of TAPA Americas, put it, “it’s not going to be a trend until we see it for maybe two or three quarters consecutively”, but Keith Lewis’s line is the one worth sitting with: “lower incident volume should not be mistaken for lower risk.” (FreightWaves)

Spec-block graphic comparing CargoNet's reported cargo-theft and fraud losses: $135.7 million in Q2 2025 versus $304.6 million in Q2 2026, more than double year-over-year, per CargoNet's Q2 2026 report.

Federal numbers point the same direction on dollars, though not on volume. The FBI’s IC3 put estimated 2025 cargo theft losses across the US and Canada at nearly $725 million in its April 30, 2026 public service announcement, a 60% jump over 2024, and it recorded confirmed incidents rising 18% over that span. CargoNet’s quarterly count moved the other way on incident volume, which is what two trackers with different scopes and different reporting periods tend to do. The dollars are the part they agree on. What makes those losses a breach story rather than a trucking story is the mechanism the FBI documents: spoofed broker emails, remote-access software, and stolen credentials. This is theft by login, not by forced lock.

Four-step flow diagram of the FBI-documented cyber-enabled cargo theft scheme: phishing emails trick victims into installing remote-access software; criminals use the compromised accounts to post fraudulent loads on load boards; posing as legitimate carriers, they accept real shipments and double-broker them; complicit drivers divert and resell the cargo.

The FBI laid out the cyber-enabled scheme step by step:

  1. Spoofed broker-agreement phishing emails trick victims into installing remote-access software.
  2. Criminals use the compromised accounts to post fraudulent loads on load boards, sometimes in the tens of thousands.
  3. Posing as legitimate carriers, they accept real shipments, double-broker them, and alter bills of lading.
  4. Complicit drivers divert and resell the cargo, sometimes with a ransom demand attached.

We’ve covered this territory before. Our own reporting from May detailed how a Chicago-area freight fraud scheme moved more than $10 million in stolen copper and liquor shipments through carrier and broker impersonation, not a system breach.

That case and this one are different attacks: one is identity fraud built on phishing, the other is a claimed intrusion into a company’s systems.

But they share a common thread worth naming plainly: freight and logistics companies are being targeted from every direction right now, and the industry’s trust-based, fast-moving nature is exactly what makes it an attractive target.

If you want the mechanics of how that broker-impersonation scheme actually worked, that piece is the deep dive; we’re not re-running it here.

What This Means / Practical Steps

None of this requires panic. It requires attention to the specific gaps this incident and this year’s trend data both point at.

  • Treat vishing as a real threat, not a theoretical one. Train dispatch, billing, and anyone who takes inbound calls to never provide a login, MFA code, or password over the phone, even to someone who sounds like they’re from your own IT department. Verify through a known internal channel, not the caller’s word.
  • Lock down MFA the right way. Push-based MFA and SMS codes can be phished through fake login portals. Where possible, move toward phishing-resistant MFA (hardware keys or app-based approval with number matching) on email and cloud storage accounts.
  • Know what a real incident response plan looks like before you need one. If your business had a confirmed intrusion tomorrow, would you know who to call, what to contain first, and when to loop in law enforcement? Our guide on what an incident response plan actually is is a good starting point if you don’t have a documented one.
  • Ask your carriers and vendors about cyber insurance and security posture, not just rates. For carriers specifically, our breakdown of trucking cyber insurance requirements covers what’s increasingly expected, and it’s built on the same FBI cargo-theft data cited above.
  • Check whether your own credentials are already exposed. Breaches at vendors and partners are how a lot of stolen credentials end up on the dark web long before anyone notices a problem. That’s a five-minute check, not a project.

The Bottom Line

Here’s what we know for certain: Uber Freight had a real security incident, confirmed it publicly, and says it’s contained.

Here’s what we don’t know: whether the “nearly 1 million files” figure is accurate, what data was actually taken, or whether a ransom changed hands.

Both of those things can be true at once, and the honest answer to “how bad is this” is that nobody outside Uber Freight and Helix currently knows, including us.

Three independent data points, all pointing the same direction:

  • The FBI’s own numbers show freight and logistics companies had a rough 2025.
  • CargoNet’s latest quarter shows cargo-fraud losses more than doubled year-over-year.
  • Right here in Chicago, one of the largest freight brokerages in the country is dealing with a claimed breach of the exact systems (email, AP/AR, dispatch) that every logistics operation runs on.

That’s worth taking seriously whether or not you’ve ever done business with Uber Freight directly.

LeadingIT is a Chicagoland managed IT and cybersecurity provider, and we work with logistics operations, manufacturers, and other regional businesses to close exactly the gaps this kind of incident exposes: MFA hardening, vendor risk review, dark web credential monitoring, and incident response planning.

If this story made you wonder how your own dispatch, billing, or email systems would hold up, that’s the right instinct to act on. Give us a call at (815) 308-2095 or visit our Chicago cybersecurity services page to talk through where your gaps are.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.