Uber Freight keeps on trucking after extortion crew breaks in
- ID
- 13533
- Status
- summarized
- Published
- 12 Aug 2026, 10:32 PM
- Fetched
- 12 Aug 2026, 11:38 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/08/12/uber-freight-keeps-on-trucking-after-extortion-crew-breaks-in/5286782
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 5.5
- Created
- 13 Aug 2026, 12:48 AM
- Tags
- Audience
- developerssaas_founders
What happened
Uber Freight is investigating a data breach claimed by the Helix extortion group, which says it stole nearly 1 million files from mailboxes, OneDrive accounts, and accounts receivable systems. Uber Freight says operations were never disrupted and the incident was contained. Helix is linked by Google Threat Intelligence to a cluster (UNC6671) that uses vishing—posing as IT helpdesk staff—to run device code phishing against employees, then siphons data from Microsoft 365 and Okta.
Why it matters
If your org uses Okta or Microsoft 365, this is a concrete reminder that device code phishing via fake IT helpdesk calls is an active, working attack path—not a theoretical one. Train staff to reject unsolicited device code prompts and verify any 'mandatory security migration' call through an internal channel before entering codes.
Discussion angle
The device code phishing + helpdesk vishing combo bypasses MFA because the attacker gets an authenticated session, not just a password—what would actually stop this in a small team that can't afford a full SOC?