Google ties the Uber Freight hackers to a $10.6 million vishing operation
Google’s threat intelligence team has connected the Helix ransomware gang, responsible for the Uber Freight breach disclosed this month, to a $10.6 million extortion operation that has systematically targeted institutional finance, logistics, and technology firms using sophisticated voice phishing tactics. The link reveals a coordinated campaign using multiple operational aliases and consistent attack methods that bypass multi-factor authentication, creating material risk for institutional investors and their service providers across multiple sectors.
- Helix claimed to steal approximately one million files from Uber Freight mailboxes, OneDrive accounts, and accounts receivable repositories, beginning public disclosure on August 6.
- Google traced the group to $10.6 million in ransom bitcoin collected between January and May across multiple victim organizations and operational aliases.
- The attackers use phone-based social engineering to impersonate IT staff, directing targets to fake login pages that harvest credentials and multi-factor authentication tokens for cloud platform access.
- $10.6M Bitcoin ransoms collected by the group from January through May across multiple victims
- 1M Stolen files allegedly exfiltrated from Uber Freight systems and repositories
- $17B Annual goods moved by Uber Freight, representing scale of potential operational impact
Uber Freight, the logistics subsidiary of ride-hailing company Uber and one of North America’s largest managed-transportation networks, confirmed a data security breach involving unauthorized system access in early August but disclosed no ransom demand or payment.
The company said it contained the incident without operational disruption, though the attackers’ public leak site subsequently featured approximately one million files allegedly drawn from email accounts, cloud storage repositories, accounts receivable databases, and internal dispatch systems.
Timestamps on some leaked documents clustered around mid-June, suggesting the breach may have occurred weeks before detection and public disclosure.
The incident disclosure came as Google’s Threat Intelligence Group published a report linking the Helix operation to a far broader extortion campaign operating under multiple names including UNC6671, Redact, Pink, and Falcon. The researchers traced all variants back to a single operational group that previously operated under the BlackFile banner before retiring that brand in May 2026.
This consolidation of aliases under one threat actor reveals a sophisticated organization managing parallel attack campaigns across multiple vertical markets.
Google Links Four Operational Aliases to Single $10.6 Million Ransomware Crew
Google’s attribution connects Helix directly to UNC6671 and its subsidiary operational names through consistent attack methodology and bitcoin wallet analysis spanning six months of activity.
Between January and May 2026, the researchers identified at least $10.6 million in ransom payments flowing to wallets controlled by the group, a figure substantially larger than most individual ransomware incidents and suggesting either multiple simultaneous extortions or repeat victimization across a portfolio of targets.
The crew’s ransomware-as-a-service model using multiple public personas allows operational flexibility and complicates victim coordination and law enforcement response.
The transition from manufacturing, healthcare, and insurance targeting in spring to technology, transportation, and hospitality sectors in June marks a deliberate strategic shift toward higher-value institutional targets and companies managing critical infrastructure.
This pivot aligns with the timing of the Uber Freight breach and demonstrates the group’s willingness to retarget based on victim sector profitability. The shift also suggests vulnerability in logistics and technology firms’ security posture relative to manufacturing and healthcare sectors that may have invested more heavily in ransomware defenses following prior high-profile campaigns.
Vishing Calls Impersonating IT Staff Bypass MFA by Harvesting Tokens Directly
The attack methodology relies on phone-based social engineering rather than technical exploits, with operators calling targets on personal mobile devices and impersonating IT helpdesk personnel to initiate mandatory security migrations.
Targets are directed to fraudulent login portals where adversary-in-the-middle tooling intercepts both passwords and multi-factor authentication tokens in real time, completely circumventing organizations’ MFA controls.
This approach succeeds because it exploits the authentication process itself rather than attempting to crack or bypass it, making it effective even against environments with strong credential policies.
Once tokens are harvested, attackers gain direct access to cloud environments, primarily Microsoft 365 and Okta platforms, allowing lateral movement through corporate repositories and high-value data repositories like email, file storage, and financial records.
The method’s effectiveness against institutional targets became visible in August when vishing attempts targeted major Wall Street hedge funds including Point72, Citadel, Two Sigma, and Millennium Management.
While those firms reported that client data remained secure, the targeting of multi-billion-dollar asset managers signals that the group views elite institutional finance as viable victim terrain despite presumed security sophistication.
In February 2026, blockchain lender Figure Technology publicly confirmed a breach following a social engineering attack where employees were manipulated into granting file system access, indicating the campaign targeting financial services companies extended well beyond hedge funds into fintech and crypto-adjacent institutions.
The consistency of successful attacks across disparate institutional sectors suggests either systematic gaps in employee security training or the sophistication of the attackers’ pretexting scripts.
Ransomware Rebranding May Obscure Attribution and Complicate Victim Coordination
The operational structure, where Helix, UNC6671, Redact, Pink, and Falcon represent the same underlying organization with different public personas, creates significant attribution and victim coordination challenges.
Victims of Helix breaches may not immediately recognize that their attackers operate under other names, preventing information sharing with organizations breached by Redact or Pink variants. This fragmentation also complicates law enforcement efforts to build cumulative cases against the organization and raises the threshold for regulatory action or sanctions.
The retirement of the BlackFile brand and consolidation under new aliases suggests operational adaptation in response to law enforcement scrutiny or reputation damage. Rebranding is a common tactic among ransomware operators facing decreasing victim willingness to negotiate with well-known gang names.
The cycle of alias rotation and brand retirement means that threat intelligence and attribution must continuously update to track the same underlying operator under new public-facing identities.
Institutional Targets Face Escalating Risk in Transportation and Technology Sectors
The group’s explicit sector pivot toward transportation and technology in June, combined with demonstrated success against Uber Freight and hedge funds, indicates institutional investors with exposure to logistics companies or technology firms managing distributed workforces face material risk.
The vishing methodology’s reliance on social engineering rather than technical exploits means no patch cycle or infrastructure upgrade can eliminate the attack surface. Organizations cannot simply apply security updates or architectural changes to defend against attackers who exploit human judgment.
Institutional investors evaluating portfolio companies and investment targets should assess whether logistics, fintech, and enterprise software firms have implemented layered defenses beyond standard MFA, including behavioral analytics, impossible travel detection, and mandatory callback verification protocols for IT support requests.
The $10.6 million ransom tally also raises questions about whether affected firms, particularly smaller ones without ransomware insurance, will face pressure to negotiate and pay, potentially funding further operations and targeting within the same sectors.
Google’s report was published on August 7, shortly after Uber Freight’s public disclosure, but the group remains active with ongoing targeting of institutional finance and logistics firms. Law enforcement agencies including the FBI have been engaged according to Uber Freight’s statement, though no public arrests or indictments have been announced. Institutional investors should monitor whether regulatory bodies including SEC or FINRA issue guidance on ransomware incident disclosure and whether the Department of Justice names specific sanctions targets tied to the Helix operation, as such action would directly constrain ransom payment routes and may signal enforcement escalation.