AI Weekly Malaysia

Back to items Summaries

Uber Freight reportedly investigating after hacking group claims data breach

ID
13567
Status
summarized
Published
13 Aug 2026, 1:15 AM
Fetched
13 Aug 2026, 1:49 AM
Provider
TechCrunch
Category
technology
Original URL
https://techcrunch.com/2026/08/12/uber-freight-reportedly-investigating-after-hacking-group-claims-data-breach/
Source URL
https://techcrunch.com/feed/

Summary

Score
4.5
Created
13 Aug 2026, 1:52 AM
Tags
Audience
developerssaas_founders

What happened

A hacking and extortion group called Helix claims to have breached Uber Freight, exfiltrating mailboxes, cloud storage, accounts payable files, and dispatch documents dated around mid-June. Uber Freight says operations are unaffected and has not confirmed the breach. Google tracks Helix under the umbrella UNC6671 and reports the group has made at least $10.6 million in ransom payments between January and May 2026, primarily using voice phishing against IT helpdesks to reset employee passwords.

Why it matters

The practical takeaway is the attack vector, not the victim: Helix gains cloud access by calling IT helpdesks and socially engineering password resets. If your team or startup operates a helpdesk or identity reset workflow, this is a concrete reason to enforce callback verification or MFA re-authentication before any password reset, rather than relying on the caller's claimed identity.

Discussion angle

How would your own password-reset or IT-helpdesk process hold up against a determined voice phishing call, and what's the cheapest control to add that blocks this specific tactic?

Top