Startups

Uber Freight investigates unauthorized access after Helix data claim

Uber Freight says the incident was contained with no operational disruption, while Helix’s claim of nearly 1 million files remains unverified.

Theo Nakamura

By Theo Nakamura · Staff Writer

· 2 min read

Uber Freight investigates unauthorized access after Helix data claim
Photo: TechCrunch

Uber Freight data breach reports stem from an acknowledged security investigation, but the scope of any data exposure remains unclear. Uber Freight said unauthorized access affected part of its systems and repositories, while a group calling itself Helix has made unverified claims about files it says it obtained.

For investors watching Uber Technologies, the immediate company message is that freight operations have continued without disruption. Uber Freight spokesperson Sam Hallock told Reuters that the incident had been identified, contained and remediated, and that the company had promptly involved federal law enforcement.

Hallock said Uber Freight’s systems were secure and fully operational. The company said the unauthorized access had not affected its business operations, according to Reuters.

What has Uber Freight confirmed about the cybersecurity incident?

Uber Freight has confirmed that it is investigating unauthorized access to a portion of its systems and repositories. It has also said its response contained and remediated the incident, and that its freight business is operating normally.

That confirmation does not establish what information, if any, was taken. In the statements reported by Reuters and TechCrunch, Uber Freight did not authenticate the files Helix posted or confirm the categories of information the group alleged it had accessed.

What Helix is claiming

Reuters reported that Helix posted material on its website on Aug. 6 that it said included nearly 1 million Uber Freight files. Uber Freight did not comment to Reuters on whether those purported files were genuine, when it learned of the incident from the group, or whether it had interacted with the group.

TechCrunch reported that Helix alleged it had obtained mailboxes, cloud-storage drives, accounts-payable records and dispatch documents. TechCrunch said it examined some purported files that appeared to contain correspondence between Uber Freight and several customers, but could not immediately verify that the material was authentic. The files it reviewed appeared to be from around mid-June, according to the publication.

Uber Freight also had not said in the statements reported by Reuters and TechCrunch whether it had received messages from Helix or paid the group.

How the incident fits a wider campaign

Helix is among several labels linked to a broader set of high-profile hacking activity, Reuters reported, citing an Aug. 6 Google Threat Intelligence post. Reuters said the wider campaign had targeted prominent U.S. companies and financial institutions in recent weeks.

That context does not determine how Uber Freight was accessed or verify Helix’s specific claims. The confirmed facts so far are narrower: Uber Freight is investigating unauthorized access, says it has addressed the incident, and reports no disruption to its operations.

This story draws on original reporting from TechCrunch.

More from Startups

All Startups