The Scam Call Pretending to Be Your IT Desk
Uber Freight has confirmed someone got into part of its systems and repositories without permission. The company says it found the intrusion, contained it, remediated it, and called in federal law enforcement. Freight operations are running normally.
The breach isn't really the interesting part. What matters is how the group claiming it usually gets in, because that same trick is being pointed at regular people right now.
Claimed versus confirmed
A group calling itself Helix listed Uber Freight on its leak site on August 6, saying it took nearly a million files from several repositories — mailboxes, OneDrive accounts, accounts-receivable material.
Uber Freight hasn't verified any of it or said what data was involved. That gap is worth holding onto. Attackers post leak claims to pressure companies into negotiating, and a company has to work out what was actually reached, and whether anything left, before it can say anything definitive. Uber's ride-hailing and delivery businesses weren't touched.
How this group works
Google Threat Intelligence Group files Helix under an activity cluster it calls UNC6671, and researchers have tied Helix, Falcon, Pink and Redact together through shared phishing infrastructure.
Their signature move is impersonating corporate help desks — phone calls plus fake login portals. It works well enough that UNC6671 collected at least 10.6 million dollars in ransoms between January and May of this year.
Why you should care personally
Help-desk impersonation isn't a technical exploit. It's a social one, and it transfers to any organisation with a support line: your bank, your employer, your carrier, your email provider.
The call has a shape you can learn. Someone rings claiming to be IT, or support, or the fraud team. They mention something plausible — a login attempt from an odd location, a locked account, a charge you don't recognise. They make it urgent. Then they send you to a login page, or ask you to read back a code.
People underestimate the fake portal. It looks right because it was copied from the real thing, pixel for pixel. You type your password into it while the attacker types the same password into the genuine site, and they're inside before you've hung up.
The one rule that beats all of it
Never authenticate during a call you didn't make. Not through a link they texted you. Not on a page they walked you to. Not by reading a code aloud.
Hang up. Get the number yourself — off the back of your card, or by typing the company's address into your browser by hand. Call that. If the first call was real, you've lost two minutes.
And treat verification codes exactly like passwords, because functionally that's what they are. No real support desk will ever ask you to say one out loud.
If you deal with Uber Freight
Watch for follow-on phishing that name-drops the incident. Attackers love using breach news as a pretext for round two, and someone who knows real details about your account is a lot more convincing than a cold approach.
For everyone else: the lesson is the method, not the victim. A crew clearing eight figures a year with phone calls and cloned login pages isn't going to stop at logistics companies.
Image: Pavel Danilyuk, via Pexels





