AERIOXFLUX
Tech & Culture
Tech & Culture · cybersecurity

The Crew That Hit Uber Freight Made $10.6M in Five Months

Helix claims nearly a million files from Uber Freight. The more useful detail is how the group gets in — and that it almost never involves an exploit.

Flux Desk·2026-08-14·5 min read

The extortion group calling itself Helix posted a claim on August 6, 2026 that it had stolen nearly one million files from Uber Freight. The company confirmed a security incident on August 12, saying it had been identified, contained, and remediated, that federal law enforcement was engaged, and that operations were unaffected.

Uber Freight has not said whether the files are authentic, what they contain, or when it first learned of the intrusion. It has not confirmed whether a ransom was demanded or paid.

The interesting part of this story is not the file count. It is the group.

Who Helix is

Google tracks Helix as part of a broader collective designated UNC6671, which researchers say shares infrastructure with several other extortion brands — including ones operating as Pink, Redact, and Falcon.

Between January and May 2026, that cluster is assessed to have collected at least $10.6 million in ransom payments.

The multi-brand structure is worth understanding because it is now standard practice rather than an oddity. A single operational group runs several public-facing identities simultaneously. Each brand has its own leak site, its own naming conventions, its own apparent history. Underneath, the same people use the same infrastructure and the same playbook.

This serves several purposes at once. It makes attribution harder for defenders and researchers. It insulates the operation when one brand attracts law enforcement attention — retire the name, keep the crew. And it lets the group tailor its public persona to the target, which matters when you are trying to convince a Fortune 500 general counsel that paying you is the rational choice.

The access method is the story

Helix's documented initial access techniques are vishing and device code phishing. Its targets are cloud services and identity infrastructure.

Read that list again and notice what is absent. No zero-day. No unpatched appliance. No supply chain implant.

Vishing is a phone call. Someone rings an employee — very often the help desk — and talks their way into a credential reset, an MFA re-enrollment, or a session. It works because help desks exist to be helpful and because the social engineering has gotten extremely good, frequently supported by real information about the target organization gathered in advance.

Device code phishing abuses a legitimate authentication flow designed for devices with no convenient input method — smart TVs, IoT hardware, CLI tools. The user is shown a short code and asked to enter it on a separate device to authorize the session. An attacker initiates a device code flow and persuades the victim to complete it. The victim then authenticates against the real identity provider on the real login page, and the resulting valid token lands in the attacker's hands.

There is no malicious page to detect. No credentials to steal. Multi-factor authentication does not help, because the victim genuinely completes it — they simply complete it for the attacker's session.

This is why the technique is spreading so fast. It defeats the specific control that most enterprises spent the last five years deploying as their answer to phishing.

Why logistics

Uber Freight is a digital freight brokerage — it matches shippers with carriers, handles the paperwork, and moves the money. Its systems hold rate agreements, carrier and shipper contact data, invoices, and the operational record of who is moving what, where, for how much.

That is a rich dataset, and it is rich in a way that compounds. A freight broker sits at the center of a network. A breach at one broker exposes information about hundreds of carriers and shippers who were never themselves attacked.

The CEVA Logistics incident from July 29 made the same point in a different way: an attack that disrupted eight European warehouses and affected entities including Bol, De Bijenkorf, ING, Ace & Tate, Ajax, and Valve. One logistics provider compromised, a long list of downstream brands exposed.

Logistics is being targeted because it is a concentration point. It also has an unusually low tolerance for downtime — freight that stops moving costs money by the hour — which extortion crews correctly read as leverage.

The response, read carefully

Uber Freight's statement is well-constructed and worth parsing precisely.

"Identified, contained, and remediated" describes the intrusion's lifecycle, not its scope. "No impact to business operations" and "systems are secure and fully operational" are both true and both about availability — they say nothing about what was taken.

That distinction matters, because for a modern extortion group availability is not the objective. The old ransomware model encrypted systems and sold the decryption key; disruption was the leverage. The current model exfiltrates data and sells silence. Under that model, a target whose operations continue perfectly and whose customer data is sitting on a leak site has suffered the full intended harm.

Nothing in Uber Freight's statement is misleading. It simply answers a question that is no longer the important one.

What actually stops this

The uncomfortable conclusion for security teams is that the controls which stop UNC6671 are not the ones most budgets are aimed at.

Device code phishing is largely solved at the policy layer: disable the device code authentication flow entirely for user accounts that never legitimately need it, which is nearly all of them. It is a configuration change, and it is one of the highest-leverage identity controls available today.

Vishing is solved at the process layer. Help desk verification procedures that cannot be talked around. Out-of-band confirmation for MFA re-enrollment and credential resets. Callback verification to numbers of record rather than numbers the caller provides.

Neither is a product. Neither shows up well in a security tooling budget. Both work.

The read

A group with no exploit development capability, using a phone and a legitimate OAuth flow, collected $10.6 million in five months and is now claiming a million files from a major logistics platform.

That is not a story about sophisticated adversaries. It is a story about identity infrastructure that assumes the human at the keyboard is the person the token belongs to — and about attackers who figured out it is far cheaper to ask than to break in.

#uber-freight#helix#unc6671#extortion#identity-security

The state of AI, in flux.

The directory + magazine for AI tools and the workflows people use to make money with them.

🔥 The Sauce Drop

The week's highest-earning AI workflows, in your inbox.

Some outbound links are affiliate links — Flux may earn a commission at no cost to you; this never affects rankings. Earnings figures are self-reported and not guarantees of income; most people earn less, some earn nothing.