
Uber Freight Says Operations Continued Despite Reported Cyberattack
Uber Freight recently confirmed that its systems were affected by a cyberattack involving the compromise of company data files. Despite the incident, the company said its operations continued uninterrupted.
The attack reportedly occurred on August 6, 2026, with cybercriminals claiming to have obtained more than 1 million files from company mailboxes, accounts receivable systems, OneDrive accounts, and other data repositories.
Federal law enforcement was notified of the incident. A hacking and extortion group known as Helix later claimed responsibility. Security researchers have linked Helix to infrastructure associated with the former BlackFile extortion group.
BlackFile reportedly retired its name in May, although similar techniques have continued to appear among other cybercriminal groups. Google researchers have reportedly associated several of these groups under the designation UNC6671.
One of the key tactics used in attacks of this type is known as vishing, or voice phishing. In these schemes, attackers may pose as members of a company's IT department and contact employees by phone. Victims can then be directed to fraudulent login pages designed to resemble legitimate internal company portals.
Why Freight Companies are Increasingly Attractive Targets
Uber Freight says it manages more than $17 billion in shipments annually. Modern freight platforms often contain more information than shipment details alone.
Depending on the systems involved, data repositories may contain:
Carrier information
Invoices and payment records
Route and transportation details
Load and transport orders
Pickup locations
Delivery locations
Unauthorized access to this information could create risks beyond temporary system disruptions or ransomware attacks. Cybercriminals could potentially use compromised data to conduct targeted fraud, impersonate business partners, redirect payments, or facilitate cargo theft.
Shipment information, including origin, destination, timing, and carrier details, could potentially provide criminals with valuable intelligence for highly targeted attacks.
Uber Freight Responds to the Incident
A spokesperson for Uber Freight confirmed that the incident was discovered, contained, and remediated. However, the company did not publicly say what information may have been accessed, including whether customer, carrier, or vendor data was affected.
Uber Freight emphasized that its operations remained active throughout the incident and that its systems were not taken offline.
Maintaining operations during a cyberattack is important for the freight industry, where disruptions at major transportation companies can affect supply chains and potentially raise prices for businesses and consumers.
What the Incident Could Mean for Carriers
With cybercriminals claiming to have obtained more than 1 million files, the chief concern is how the compromised information could potentially be used.
If confidential carrier information was accessed, it could make it easier for criminals to impersonate legitimate trucking companies or industry representatives.
For example, access to dispatch records or shipment information could potentially allow attackers to create convincing fraudulent load offers or attempt to redirect cargo to thieves.
Carriers may also face an increased risk of phishing attempts involving individuals impersonating Uber Freight representatives and requesting login credentials, payment information, or account updates.
What are Your Thoughts?
The full scope of the incident remains unclear because Uber Freight has not publicly spoken about what kind of information may have been accessed.
As a result, carriers, brokers, and other industry participants may want to remain alert for suspicious communications, unauthorized account activity, fraudulent payment requests, or unusual load changes.
What are your thoughts on the Uber Freight cyberattack? Let us know in the comments.








