Your Logistics Data Is a Target: The Uber Freight Breach

Your Logistics Data Is a Target: The Uber Freight Breach — featured image

by

The Uber Freight Breach Isn’t About Uber. It’s About Your Business.

When you run a small logistics operation in Malaysia — a few lorries, a warehouse in Shah Alam, a loyal roster of clients — cybersecurity feels like a problem for the big boys. You don’t have an IT department. You don’t have a security budget. And you certainly don’t expect a hacking group to knock on your digital door.

But this week, Uber Freight — the logistics arm of one of the largest tech companies in the world — confirmed it is investigating a data breach claimed by a hacking group called Helix. The hackers say they took mailboxes, cloud storage drives, accounts payable files, and dispatch documents. Uber Freight says its systems are running normally, but the damage to customer trust is already done.

Here’s what should worry you: the hackers didn’t break in through some exotic zero-day exploit. According to Google’s tracking of the group, they get in by calling your IT helpdesk, pretending to be an employee, and asking for a password reset. That’s it. That’s the whole attack.

TL;DR: A hacking group breached Uber Freight using voice phishing — conning employees over the phone. They stole dispatch documents, mailboxes, and financial files. The same tactic works perfectly on Malaysian SMEs. If you handle delivery schedules, customer data, or supplier invoices, you are a target.

What This Means

Helix is not your average lone hacker. The group has spent the year hitting transportation companies, financial firms, and private equity houses. TechCrunch reports that Google tracks Helix as part of a wider hacking umbrella collective called UNC6671. These are organised, industrial-scale operations with a simple business model: steal data, threaten to publish it, demand a ransom.

Their method is almost embarrassingly simple. They call your helpdesk. They claim to be a staff member who forgot their password. They might already know your employee’s name, or their manager’s name, from LinkedIn or your company website. When the helpdesk resets the password, the hackers walk straight into your cloud environment. Then they quietly copy everything: emails, shared drives, dispatch records, accounts payable.

Then comes the threat. Pay up, or we publish everything online for your customers, your competitors, and the media to see.

“Security researchers have long warned that these attacks, while crude and rudimentary, are highly effective at tricking humans into granting access to sensitive systems.”

That observation, from the TechCrunch report, is the whole story in one sentence. The attack isn’t sophisticated. It’s effective because it targets the one thing your business cannot patch: human trust.

How This Applies to Malaysian SMEs

Think about what Uber Freight lost. Dispatch documents. That’s your daily delivery schedules, your route plans, your customer names and addresses. Mailboxes. That’s every email your team has sent about pricing, complaints, or late deliveries. Accounts payable. That’s your supplier invoices, your bank details, your payment deadlines.

Now ask yourself: does your Malaysian business hold any of the same? If you run a logistics company in Klang Valley, a freight forwarding operation in Penang, or a last-mile delivery service for e-commerce sellers — you absolutely do. The only difference between you and Uber Freight is that they have a cybersecurity team. You probably answer the phone yourself.

The uncomfortable truth is that Malaysian SMEs are actually a better target. Large companies like Uber Freight have layers of controls, cyber insurance, and public relations firepower. A 20-person logistics company has none of that. If a hacker publishes your customers’ addresses and delivery routes, your reputation collapses overnight. Your clients — the ones who trusted you with their supply chain — will quietly move to your competitor.

There’s also a legal angle you cannot ignore. Malaysia’s Personal Data Protection Act (PDPA) applies to businesses that process personal data. A data breach involving customer contact details is not just an embarrassment; it’s a potential regulatory headache. One incident could put you in a position where you’re explaining to clients, to the authorities, and possibly to the press why you didn’t secure a simple helpdesk line.

And here is the part most Malaysian business owners skip: the breach doesn’t stop at you. When Helix stole Uber Freight’s dispatch documents, they also got email correspondence between Uber Freight and its customers. That’s how these attacks ripple outward. Your suppliers, your sub-contractors, your clients — they all become collateral damage. In a market like Malaysia, where trust is personal and reputation travels fast, being the weak link in someone else’s supply chain is a disaster.

Practical Takeaways: The SME Security Checklist

What Hackers Target What That Looks Like in Your Business What to Do About It
Mailboxes Email conversations with customers and suppliers Enable two-factor authentication on every account today
Cloud storage drives Shared folders with delivery documents, invoices, photos Review who has access — and delete ex-staff accounts immediately
Accounts payable files Supplier invoices, bank details, payment records Restrict financial files to one or two people only
Dispatch documents Daily routes, customer addresses, driver schedules Password-protect route files and rotate the password weekly
  • Create a “no password reset over the phone” rule. Tell every employee: nobody calls and asks for passwords. Period. If someone claims to be a colleague, request a video call or in-person confirmation.
  • Turn on two-factor authentication everywhere. Email, cloud storage, accounting software. It’s free, and it makes a stolen password useless on its own.
  • Do a monthly access review. List who can see what. If a staff member left last year, their login should be dead, not dormant.
  • Drill your team on voice phishing. Run a mock call. Have someone pretend to be a supplier asking for an invoice or a password reset. See who bites, then train them.
  • Set up a simple incident plan. If you discover suspicious activity, who do you call first? Your cloud provider? Your bank? Write it down now, not during a crisis.
  • Back up critical files offline. If someone threatens to wipe your data, a clean backup means you can say no to their demands.

The Bigger Picture

What happened to Uber Freight is part of a larger pattern. Helix is not a lone outfit; it’s part of an umbrella collective that Google actively tracks as a persistent threat. The hackers are not choosing targets based on company size. They are choosing targets based on access. Every business that stores valuable data and has a human answering the phone is a candidate.

For Malaysian SMEs, the long-term lesson is that cybersecurity is no longer an IT department conversation. It is a business survival issue, as fundamental as maintaining your vehicles or keeping your licenses renewed. The companies that thrive over the next five years will be the ones that treat a staff training session on voice phishing as seriously as they treat a major client meeting.

The hackers are organised. They are persistent. And according to Google’s analysis of the group’s bitcoin wallets, they have succeeded repeatedly throughout the year. The only question left is whether your business will be the next entry on their wall — or the one that turned them away at the front door.

Ready to Streamline Your Operations?

Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →