Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Uber Freight launches cyber attack investigation following Helix claims

Uber’s logistics and cargo subsidiary is currently investigating claims of a cyber attack after a threat actor took credit for a breach of the company.

Thu, 13 Aug 2026
Uber Freight launches cyber attack investigation following Helix claims

Speaking with Reuters, a spokesperson for Uber Freight said that an investigation into the cyber attack has begun and that its operations have not been impacted.

“We are investigating a data security incident involving unauthorised access to a portion of Uber Freight’s systems and repositories. The incident was identified, contained, and remediated, and we promptly engaged federal law enforcement,” the spokesperson said.

“There has been no impact to Uber Freight’s business operations, which continue in the normal course without disruption. Our systems are secure and fully operational.”

 
 

The cyber incident was claimed by the Helix hacking group, which posted data it claims was stolen from Uber Freight.

Helix claimed cyber attacks on a number of Wall Street firms this month, including Blackstone, the firm looking to buy HSBC’s Australian lending portfolio.

Sources close to the matter named Two Sigma Investments and Citadel as among the hedge funds targeted, with further investigation revealing several other firms.

While previous incidents involved AI-powered voice phishing (vishing) attempts, attempts targeting firms, including Blackstone, Apollo Global Management, Bain Capital, CME Group, Moody’s, Clearlake Capital, KKR, TPG, and Bridgewater Associates, involved fake websites that aimed to steal credentials from company staffers.

According to a Google blog post, several companies paid ransom to Helix, which operates under a number of different monikers, including Pink, Falcon, and Redact.

The bank staffers were reportedly told by the hackers that IT had given urgent orders to update multifactor authentication and passkeys, and directed them to the malicious sites. If the staff followed instructions, they would hand over their passkeys and credentials.

The Google blog post said the threat actors had recently increased their targeting of financial institutions and law firms, adding that they were purely motivated by profit.

“Really, it’s a money thing,” said Austin Larsen, principal threat analyst at Google.

“They think that these firms or organisations have data sensitive enough that, if taken, they would pay to prevent it.”

While Google did not name the victims, Reuters found malicious domains related to the victims on the fake websites.

“They all were likely used in attempted intrusions,” Larsen said generally about the incident.

“They were not all successful.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: