Threat Intelligence Brief
Curated summary with source attribution
Source: techcrunch.com
Threat Risk: High
Victim: Uber Freight
Incident: Data breach and extortion attempt.
Impact: Potential exposure of customer correspondence, financial documents, and internal dispatch files.
Attacker: Helix (UNC6671)
Analysis: The Helix group, tracked as UNC6671, is leveraging vishing to bypass security by tricking IT helpdesks into resetting employee passwords. Once inside, they target cloud environments to steal high-value corporate documents for extortion. This campaign demonstrates a strategic focus on the transportation and financial sectors.
Recommendations: Implement phishing-resistant multi-factor authentication (MFA) to reduce reliance on password resets.; Establish strict, multi-step identity verification protocols for IT helpdesk account recovery requests.; Enhance monitoring for anomalous data exfiltration patterns within cloud storage environments.
Source: TechCrunch
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source
Latest Developments
Update — 2026-08-12 22:17 UTC
Data breach and extortion claim involving the theft of nearly 1 million files. Potential exposure of mailboxes, OneDrive accounts, and accounts receivable data. The breach appears to be the work of the Helix group, linked to the UNC6671 activity cluster, which specializes in targeting cloud identity infrastructure. The attackers likely utilized vishing and device code phishing to gain initial access to mailboxes and OneDrive accounts. This incident signals a strategic shift by the group to target higher-value sectors like transportation and technology.
Corroborating source: scworld.com
Update — 2026-08-13 02:14 UTC
A data breach and extortion attempt involving the theft of internal corporate files. Potential exposure of financial records and sensitive correspondence with business partners. The Helix group, linked to UNC6671, is aggressively targeting the transportation and logistics sector using a standardized extortion playbook. By exfiltrating mailboxes and accounts payable files, they create high-leverage positions for ransom demands. This incident underscores the systemic risk facing supply chain intermediaries who manage vast amounts of third-party partner data.
Corroborating source: en.cryptonomist.ch