Uber Freight is investigating a cyber security incident after a hacking group claimed to have stolen nearly a million company files. The breach highlights ongoing vulnerabilities amid a broader wave of cyber extortion targeting major corporations across the US.
Uber Freight is investigating a cyber security incident after a hacking group claimed to have stolen a large cache of company files, according to a company spokesperson and reporting by Reuters. The logistics arm of Uber said the incident affected only a portion of its systems and repositories, while insisting there was no disruption to its business operations. The company said the issue was identified, contained and remediated, and that federal law enforcement was promptly involved.
A group calling itself ‘Helix’ said on 6 August that it had posted nearly 1 million Uber Freight files on its website. Uber Freight has not said whether the material is genuine, when it was first alerted to the breach, or whether it had any direct contact with the hackers. Google Threat Intelligence said in an 6 August blog post that Helix is one of several aliases linked to a broader wave of extortion attempts targeting prominent companies.
Reuters reported last week that dozens of major US businesses and financial institutions were caught up in that campaign, including investment firms and asset managers such as Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR and TPG, alongside CME Group, Clearlake Capital and Moody’s. Levi Strauss also disclosed in a regulatory filing on Friday that an unauthorised third party had gained access to its systems, underlining how wide the recent wave of attacks has been.
The latest episode adds to Uber’s uneven cyber security record in recent years. In 2023, a New Jersey law firm that represented Uber told affected drivers that sensitive information, including names and Social Security numbers or Tax Identification Numbers, had been exposed in an attack on its servers. Separate commentary in the security sector described that incident as one of several breaches affecting Uber or its partners over a six-month period. Uber Freight, meanwhile, has continued to push ahead with product development, unveiling an AI-focused logistics roadmap in September 2023 after investing heavily in software following its Transplace acquisition.
Source Reference Map
Inspired by headline at: [1]
Sources by paragraph:
– Paragraph 1: [2], [1]
– Paragraph 2: [2], [1]
– Paragraph 3: [1]
– Paragraph 4: [3], [4], [5], [7]
Source: Noah Wire Services
Verification / Sources
- https://www.channelnewsasia.com/business/uber-freight-says-its-investigating-cyber-incident-following-hacker-claims-6312961 – Please view link – unable to able to access data
- https://www.channelnewsasia.com/business/uber-freight-says-its-investigating-cyber-incident-following-hacker-claims-6312961 – Uber Freight is investigating a data security incident involving unauthorized access to a portion of its systems and repositories. A company spokesperson stated that there has been no impact on Uber Freight’s business operations, which continue without disruption. The incident was identified, contained, and remediated, with federal law enforcement promptly engaged. A hacking group named ‘Helix’ claimed responsibility, posting what it alleged were nearly 1 million Uber Freight files. The authenticity of the data posted by the hackers has not been confirmed, and the company has not commented on interactions with the hackers.
- https://www.infosecurity-magazine.com/news/uber-data-exposed-law-firm-breach/ – In April 2023, a New Jersey-based law firm representing Uber, Genova Burns, notified an unknown number of Uber drivers that their sensitive data had been exposed and stolen due to a cyber-attack on the firm’s servers. The breach occurred between January 23 and January 31, 2023, and involved unauthorized access to drivers’ names, Social Security numbers, and/or Tax Identification Numbers. This incident marked Uber’s third data breach in six months, highlighting ongoing cybersecurity challenges for the company.
- https://www.breachlock.com/resources/blog/third-party-security-breach-is-ubers-third-breach-in-6-months/ – In March 2023, Uber experienced its third data breach in six months, this time due to a third-party security breach. The breach occurred when New Jersey-based law firm Genova Burns, representing Uber, was attacked in January 2023. The attack compromised sensitive data of Uber drivers, including names and Social Security numbers. This incident underscores the ongoing cybersecurity challenges faced by Uber and the risks associated with third-party vendors.
- https://www.techradar.com/news/uber-has-internal-data-stolen-in-yet-another-cyberattack – In April 2023, Uber suffered another cyberattack resulting in the theft of sensitive data belonging to Uber drivers. The breach was identified in late January 2023, when suspicious activity was detected in the law firm Genova Burns’ internal information systems. An unauthorized third party accessed the firm’s systems between January 23 and 31, 2023, leading to the exposure of drivers’ personal information. This incident highlights the ongoing cybersecurity challenges faced by Uber and its partners.
- https://www.rankiteo.com/company/uber-freight – Uber Freight has a cyber risk score of 767 out of 1000, indicating a ‘Fair’ level of cybersecurity. The company has experienced multiple cyber incidents, including breaches in April 2023, January 2023, and December 2022. These incidents involved unauthorized access to systems and data leaks, highlighting the ongoing cybersecurity challenges faced by Uber Freight. The company’s risk score reflects the need for continued vigilance and improvement in its cybersecurity measures.
- https://www.prnewswire.com/news-releases/uber-freight-doubles-down-on-enterprise-technology-unveils-next-generation-product-roadmap-with-ai-powered-logistics-301941585.html – In September 2023, Uber Freight announced a comprehensive evolution of its logistics technologies, unveiling a next-generation product roadmap with AI-powered logistics. The company invested $120 million since acquiring Transplace in 2022, focusing on software designed to reimagine transportation management. The new products aim to enhance enterprise applications, including AI-powered software, to improve logistics operations. This strategic expansion underscores Uber Freight’s commitment to advancing logistics networks through innovative technology solutions.
Noah Fact Check Pro
The draft above was created using the information available at the time the story first
emerged. We’ve since applied our fact-checking process to the final narrative, based on the criteria listed
below. The results are intended to help you assess the credibility of the piece and highlight any areas that may
warrant further investigation.
Freshness check
Score: 8
Notes: The article was published on August 12, 2026, reporting on a cyber incident involving Uber Freight and a hacker group named ‘Helix’ claiming responsibility. The earliest known publication date of similar content is August 6, 2024, indicating a freshness of approximately 2 years.
However, the article references a blog post from August 6, 2024, by Google Threat Intelligence discussing ‘Helix’ as one of several aliases linked to a broader wave of extortion attempts targeting prominent companies.
Given the time lapse and the lack of recent developments or confirmations, the freshness score is reduced.
Quotes check
Score: 7
Notes: The article includes direct quotes from Uber Freight and Google Threat Intelligence. However, the earliest known usage of these quotes is from August 6, 2024, in the referenced blog post.
The article does not provide direct links to the original sources of these quotes, making independent verification challenging. The absence of direct links to the original sources raises concerns about the verifiability of the quotes.
Source reliability
Score: 6
Notes: The article originates from Channel News Asia (CNA), a reputable news organisation. However, the content heavily relies on a single source, the August 6, 2024, blog post by Google Threat Intelligence.
The lack of additional independent sources or recent updates on the incident raises concerns about the comprehensiveness and currentness of the information presented.
Plausibility check
Score: 7
Notes: The article reports on a cyber incident involving Uber Freight and a hacker group named ‘Helix,’ which is plausible given the increasing frequency of cyberattacks on major companies. However, the lack of recent developments or confirmations since August 2024 raises questions about the current relevance and impact of the incident.
The article does not provide specific details about the nature of the breach, the data involved, or the current status of Uber Freight’s investigation, making it difficult to fully assess the plausibility of the claims.
