Ransomware victim disclosure
← All victimsUber Freight
Claimed by HELIX · listed 5 days ago
Status timeline
- ListedAug 13, 2026
- Data leakeddate unknown
At a glance
- Group
- HELIX
- Status
- Data leaked
- Sector
- Transportation/Logistics
- Listed on leak site
- Aug 13, 2026
- Data size
- ~54 GB (combined across visible tiers)
About the victim
AI dossier — public-source company profileUber Freight is the freight logistics division of Uber, providing digital freight marketplace and transportation services. The company operates as part of the broader Uber platform serving commercial logistics and delivery operations.
- Industry
- Transportation & Logistics
Attack summary
Severity: critical — Confirmed exfiltration and staged publication of 54 GB of corporate data from major transportation infrastructure company, including email communications, identity systems, internal processes, and business intelligence. Data scale, sensitivity of logistics operations, and staged public disclosure pose significant operational and competitive risk.HELIX group claims to have exfiltrated corporate data from Uber Freight, including SharePoint libraries, email systems, OneDrive documents, and internal project files organized across four sensitivity tiers with staged publication. Approximately 54 GB of data is staged for progressive public release.
Data the group says was taken
AI dossier — extracted from the leak post- SharePoint libraries
- Corporate email (mailbox emails and attachments)
- OneDrive documents
- Business process documentation (Lean Six Sigma cancelled projects)
- Internal websites and portals
- Entra/identity system records
- Inventory systems
The group's post references roughly 26 downloadable file packages across 4 sensitivity tiers proof files.
What the group claims
Ransomware leak of Uber Freight data with sensitivity layers organized in SharePoint libraries (T1 least sensitive to T4 most sensitive). Data includes Entra and inventory information across multiple tiers.
The leak post
captured from the group's site- Company leak board for Uber Freight. This is the destination link from Helix Leaks. Countdown until releases; later stages unlock on schedule. Entra + inventory visible; downloads follow each stage. ## Uber Freight · Sensitivity layers SharePoint libraries · T1 (least) → T4 (most). Stage packages unlock when each timer hits zero. T1 Least → T2 Low → T3 High → T4 Most. T1 Other Small Sites T1 · 262.9 MB Classified package ready [ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T1/Other_Small_Sites_T1/part-001.zip) T1 Mailbox Emails T1 · 163.0 MB Classified package ready [ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T1/Mailbox_Emails_T1/part-001.zip) T2 Other Small Sites T2 · 7.16 GB Classified package ready [ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T2/Other_Small_Sites_T2/part-001.zip) [ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T2/Other_Small_Sites_T2/part-002.zip) [ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T2/Other_Small_Si…
Data the group says was taken
- mailbox emails
- mailbox attachments
- OneDrive documents
- SharePoint libraries
- Lean Six Sigma project documents
- FP&A documents
Screenshot of the leak post

Sources
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

