Helix has claimed a breach at Uber Freight, saying it took mailboxes, cloud storage, accounts payable files, and dispatch documents; Uber Freight said its operations were unaffected while it investigates. Google also said this week that it tracks Helix as UNC6671 and that the group has collected at least $10.6 million in ransom payments this year.
The group’s usual path is social engineering: callers pose as employees and talk helpdesk staff into resetting passwords. That can hand over a working login to email and cloud storage without touching the production network, which is why a company can keep moving freight while sensitive correspondence and business records are already exposed.
For logistics firms, the real blast radius sits in identity and collaboration systems, not in warehouse uptime. If helpdesk resets can open mail and file stores, then customer communications, billing records, and dispatch paperwork can be the durable loss even when core operations stay up.