Skip to main content

Ransomware victim disclosure

All victims

Uber Freight

Claimed by HELIX · listed 5 days ago

~54 GB (combined across visible tiers)
Data size
5d
Age
since listed · data leaked

Status timeline

  1. ListedAug 13, 2026
  2. Data leakeddate unknown

At a glance

Group
HELIX
Status
Data leaked
Listed on leak site
Aug 13, 2026
Data size
~54 GB (combined across visible tiers)

About the victim

AI dossier — public-source company profile

Uber Freight is the freight logistics division of Uber, providing digital freight marketplace and transportation services. The company operates as part of the broader Uber platform serving commercial logistics and delivery operations.

Industry
Transportation & Logistics

Attack summary

Severity: critical — Confirmed exfiltration and staged publication of 54 GB of corporate data from major transportation infrastructure company, including email communications, identity systems, internal processes, and business intelligence. Data scale, sensitivity of logistics operations, and staged public disclosure pose significant operational and competitive risk.

HELIX group claims to have exfiltrated corporate data from Uber Freight, including SharePoint libraries, email systems, OneDrive documents, and internal project files organized across four sensitivity tiers with staged publication. Approximately 54 GB of data is staged for progressive public release.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • SharePoint libraries
  • Corporate email (mailbox emails and attachments)
  • OneDrive documents
  • Business process documentation (Lean Six Sigma cancelled projects)
  • Internal websites and portals
  • Entra/identity system records
  • Inventory systems

The group's post references roughly 26 downloadable file packages across 4 sensitivity tiers proof files.

What the group claims

Ransomware leak of Uber Freight data with sensitivity layers organized in SharePoint libraries (T1 least sensitive to T4 most sensitive). Data includes Entra and inventory information across multiple tiers.

The leak post

captured from the group's site
- Company leak board for Uber Freight. This is the destination link from Helix Leaks. Countdown until releases; later stages unlock on schedule. Entra + inventory visible; downloads follow each stage. 
## Uber Freight · Sensitivity layers
SharePoint libraries · T1 (least) → T4 (most). Stage packages unlock when each timer hits zero.
T1 Least → T2 Low → T3 High → T4 Most. 
T1 Other Small Sites T1 · 262.9 MB
Classified package ready 
[ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T1/Other_Small_Sites_T1/part-001.zip)
T1 Mailbox Emails T1 · 163.0 MB
Classified package ready 
[ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T1/Mailbox_Emails_T1/part-001.zip)
T2 Other Small Sites T2 · 7.16 GB
Classified package ready 
[ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T2/Other_Small_Sites_T2/part-001.zip) [ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T2/Other_Small_Sites_T2/part-002.zip) [ ](http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd.onion/api/packages/download/T2/Other_Small_Si…

Data the group says was taken

  • mailbox emails
  • mailbox attachments
  • OneDrive documents
  • SharePoint libraries
  • Lean Six Sigma project documents
  • FP&A documents

Screenshot of the leak post

Leak screenshot for Uber Freight

Sources

Source

Indexed 5 days ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About HELIX

HELIX is an active ransomware group with 10 confirmed victims as of August 2026, operating one onion leak site. The small victim tally points to either a recent entry or selective targeting. The group has been linked to 18 public disclosures across our corpus. The operation is currently active.

Timeline of this disclosure

  • August 13, 2026Uber Freight listed by HELIXon the group's public leak site
Data size
~54 GB (combined across visible tiers)

Sector and geography

This disclosure adds to ransomware activity in the Transportation/Logistics sector, which has 1,081 disclosures indexed across all operators we track.

If your organisation is affected

A listing by HELIX means Uber Freight appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Monitor for the data appearing on HELIX's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.