Uber Freight is investigating a data-security incident involving unauthorised access to part of its systems, the company said on Tuesday, five days after a hacking group claimed to have posted around a million of its files online.
In a statement attributed to spokesperson Sam Hallock, the company said there had been “no impact to Uber Freight’s business operations, which continue in the normal course without disruption” and that “our systems are secure and fully operational”.
Hallock said the incident had been “identified, contained and remediated”, and that the company had “promptly engaged federal law enforcement”.
Moreover, Hallock declined to confirm whether the posted data was authentic, or to say when the hackers first made contact. Uber Freight has neither confirmed nor disputed the claim that a million files were taken.
The claim was posted on 6 August by a group calling itself Helix, one of four aliases, along with Falcon, Pink and Redact, that Google’s Threat Intelligence Group tracks under an actor it designates UNC6671.
Google published research on the group the same day, describing a voice-phishing campaign in which callers impersonate IT staff to obtain access to large financial firms.
It named Apollo Global Management, Bain Capital, Blackstone, Bridgewater, CME Group, KKR, Moody’s and TPG as targets, with ransom demands of between $750,000 and $3m.
Google’s research does not mention Uber or Uber Freight; the connection to that campaign rests on the Helix name alone.
The group’s tactics, according to Google’s researchers, rely on social engineering rather than technical intrusion, with callers persuading employees to grant access or reset credentials.
One cryptocurrency wallet linked to the campaign received around $10m in bitcoin earlier this year.
No independent researcher has verified the leaked data, and no specialist security outlet had reported on the incident at the time of writing.
Uber Freight brokers freight, sells transportation-management software and runs managed transportation for shippers, so its systems hold contract, pricing and carrier records, but what was taken has not been established.
Whether any personal data of drivers, employees or customers is involved is not known, and nothing in the reporting suggests Uber’s ride-hailing or delivery systems were affected.
Uber Freight is a subsidiary of Uber Technologies, launched in 2017 and expanded through the $2.25bn acquisition of Transplace in 2021. It reported $1.583bn in revenue in the second quarter of this year, up 25%, while posting an operating loss of $24m.
Uber bought out Greenbriar Equity’s stake for $851m in October 2024, four years after the private-equity firm led a $500m investment that valued the unit at $3.3bn.
The unit has grown quickly through acquisitions and now handles freight for large shippers across North America, but has yet to turn a profit in any quarter since the Transplace deal. Uber does not break out Uber Freight’s results in detail in its own earnings.
Uber has a difficult history with breach disclosure. The company concealed a 2016 breach affecting 57 million users and drivers, paying the hackers $100,000.
It settled with all 50 US states and the District of Columbia for $148m in 2018, and its former chief security officer, Joe Sullivan, was convicted in 2022 and sentenced in 2023 to three years’ probation for covering it up.
Separately, the Dutch data protection authority fined Uber €290m in 2024 over transfers of driver data to the US.
Uber has not filed a securities disclosure specific to the incident, and no material share-price move has been tied to it.
Get the TNW newsletter
Get the most important tech news in your inbox each week.