The group has posted alleged samples of the data on its leak site . Uber Freight has not independently verified the authenticity of all the files Helix posted
.
Helix is a financially motivated data-extortion group, not a ransomware-encryption gang in the traditional sense . It operates as a semi-closed Ransomware-as-a-Service (RaaS) platform with an estimated 5–15 affiliates, not an open-market brand like LockBit
.
Helix specializes in identity-centric intrusions against enterprise cloud environments, particularly Microsoft 365 and SharePoint . Known tactics include:
Helix operators have been observed impersonating a target's direct manager by name on caller ID . Once inside, they register new MFA apps for persistence, then enumerate and exfiltrate files from SharePoint .
Researchers at ReliaQuest and Google Threat Intelligence Group link Helix to a broader cybercriminal cluster tracked as UNC6671 . Helix is believed to have emerged from the BlackFile and ShinyHunters ecosystem, with ties to other brands including Redact, Pink, and Falcon
. These groups are known to fragment, rebrand, and share infrastructure and affiliates
. Google tracked the cluster as collecting over $10.6 million in ransom payments between January and May 2026 .
There is no publicly confirmed total for Helix's specific ransom earnings from the Uber Freight incident. Analysts estimate the group has posted at least 10–15 victims on its leak site since emerging in mid-2026, spanning transportation, financial services, and other sectors . Helix's data-extortion model typically involves pressuring victims to pay by leaking stolen data rather than encrypting systems
.
The Uber Freight breach illustrates how threat actors have moved from exploiting software vulnerabilities to exploiting identity and trust. Helix's playbook — voice phishing to obtain credentials, device code attacks to bypass MFA, and automated cloud exfiltration — works against organizations that have invested heavily in traditional endpoint and network defenses.
Key takeaways:
Helix is not a lone wolf. It is the latest brand in a rapidly evolving cybercriminal ecosystem that fragments and rebrands to avoid attribution and disruption. The group's success against a sophisticated company like Uber Freight — which runs a $17 billion logistics network — underscores how hard it is to defend against social engineering when attackers target the people who have access to the data, not the systems that store it.