Uber Freight Data Breach Claims Spark Investigation as Extortion Gang Takes Credit

TL;DR
- Uber Freight has confirmed it is investigating claims that an extortion group breached its systems and stole internal data, but says it has not yet verified the hackers' allegations.
- The gang behind the claim is known for double-extortion attacks targeting the transportation, logistics, and private equity sectors, typically threatening to leak sensitive data if a ransom is not paid.
- While no customer freight data has been confirmed compromised, the incident highlights growing cybersecurity risks in the logistics industry where shipment, pricing, and carrier data is highly valuable on the black market.
The Investigation So Far
Uber Freight, the logistics and supply chain arm of Uber Technologies, said this week it is actively investigating claims that it suffered a data breach after an extortion group listed the company on its dark web leak site. The company has not confirmed that a breach occurred and said its freight operations and customer-facing platforms remain operational.
In a statement, Uber Freight said it became aware of the allegations after the threat actors posted samples of what they claim is stolen corporate data and set a deadline for ransom payment. The company said it has engaged its internal security team and brought in third-party cybersecurity experts to assess the legitimacy of the claims and to determine if any of its systems were actually compromised.
As of now, there is no evidence of disruption to Uber Freight's transportation management system or its shipper and carrier networks, but the investigation is ongoing.
Who Is Behind the Claim?
The group claiming responsibility is part of a new wave of financially motivated extortion gangs that have shifted away from traditional ransomware encryption toward pure data theft and extortion. Unlike older ransomware operations that lock files, these groups exfiltrate data and threaten to publish it unless the victim pays.
Security researchers note this particular gang has built a reputation over the past 18 months for targeting transportation and logistics companies as well as private equity firms and their portfolio companies. The strategy is deliberate: logistics firms hold a trove of commercially sensitive data, while private equity-backed businesses are often seen as more likely to pay quickly to avoid reputational damage during funding rounds or acquisitions.
The group typically gains initial access through phishing, exploitation of unpatched edge devices, or stolen credentials, then spends days or weeks inside a network collecting documents before making its public demand on a leak site.
What Was Allegedly Stolen?
On its leak site, the attackers allege they exfiltrated a significant volume of data from Uber Freight, posting screenshots and file listings as supposed proof. The samples, which have not been independently verified, purportedly include internal corporate documents, employee-related information, financial spreadsheets, and logistics operational data.
The hackers claim the stolen cache contains freight invoices, rate information, customer and carrier contact details, and internal communications. Cybersecurity analysts who reviewed the teaser data say the file names and screenshots appear plausible for a logistics operation, but caution that such posts are often exaggerated or recycled from previous breaches to pressure victims into paying.
Uber Freight has not validated the authenticity of the samples and has not disclosed whether any personal or customer data is at risk, saying it will notify relevant parties directly if the investigation confirms a compromise.
Why Freight and Logistics Data Is a High-Value Target
The freight industry has become an increasingly attractive target for cybercriminals, and for good reason. A modern freight broker like Uber Freight manages massive amounts of sensitive data that is valuable both for fraud and competitive advantage.
Stolen rate confirmations, load boards, and carrier information can be used to conduct sophisticated business email compromise and freight fraud schemes, such as double-brokering scams where criminals impersonate legitimate carriers to steal loads. Customer lists, pricing contracts, and lane data could also give competitors or malicious actors deep insight into a company's operations.
Beyond direct financial crime, logistics firms are critical infrastructure. Disruption or the threat of leaking operational data can create immense pressure to pay, especially when customers trust the platform to move billions of dollars in goods.
Potential Fallout for Customers and Partners
For shippers and carriers that use the Uber Freight network, the immediate risk remains uncertain while the investigation continues. If the breach is confirmed, exposed data could lead to targeted phishing attacks, invoice fraud, or identity theft attempts using stolen employee or carrier information.
Even if the hackers' claims prove to be inflated, the incident is a reminder for all customers to practice heightened vigilance. Security experts recommend that Uber Freight customers monitor for suspicious communications claiming to be from Uber Freight, enforce multi-factor authentication on all logistics portals, and review payment procedures for any changes to banking instructions.
For Uber itself, the reputational stakes are high. While Uber Freight operates as a separate business unit, it shares the Uber brand, which has faced high-profile security incidents in the past. How quickly and transparently the company validates the claims and communicates with affected parties will be critical.
What Happens Next
Uber Freight says it will provide updates as its investigation progresses and is reportedly working with law enforcement. The next key milestone will be whether the extortion gang follows through on its threat to publish the full dataset after its payment deadline expires, a common tactic to increase leverage.
In the meantime, security analysts are watching to see if the stolen data appears on underground forums or is used in follow-on fraud. Whether or not the breach is ultimately confirmed, the incident underscores a broader trend: as freight digitizes, cybersecurity is no longer just an IT issue but a core operational risk for the entire supply chain.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!