Helix Extortion Hit Uber Freight via Helpdesk Vishing

The Register Security · Medium sophistication
Last updated August 12, 2026

Uber Freight is investigating unauthorized access after the Helix extortion group claimed it stole nearly one million files from company cloud and email repositories. Google-linked research says the broader cluster (UNC6671) commonly gets in by calling employees and posing as IT helpdesk staff running “mandatory security migrations,” then using device-code phishing to capture cloud sessions and steal data from services like Microsoft 365.

Key findings

  • Helix listed Uber Freight on its leak site and claimed it stole “nearly 1 million files.”
  • Stolen data was claimed to come from “mailboxes, OneDrive accounts, the accounts receivable department, and other repositories.”
  • Google tracks related activity as UNC6671 and says operators “often use vishing to gain an initial foothold,” pretending to be IT helpdesk staff running “mandatory security migrations.”
  • The described workflow includes calling employees “on their personal phones” and using “device code phishing” to obtain “credentials and authenticated sessions” before stealing data from cloud services like “Microsoft 365.”
  • Okta identity infrastructure has also been targeted, per Google’s write-up.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance (Accounts Receivable), IT Helpdesk/Service Desk, Identity & Access Management (Okta/M365 admins), Operations/Logistics leadership.
  • Affected industries: Transportation/logistics, Technology, Hospitality, Manufacturing, Real estate, Healthcare, Insurance.
  • Attack channels: vishing.
  • Impersonated: IT helpdesk staff.

Awareness takeaways

  • Treat unsolicited “IT helpdesk” calls about mandatory migrations as suspicious and verify using a known internal channel before doing anything.
  • Never complete a device-code sign-in (or share any login codes) because it can give attackers a fully authenticated session to company cloud data.
  • Assume cloud repositories (mailboxes and OneDrive) are prime targets and reinforce reporting when users notice unusual access or consent prompts.
  • Train identity admins to be alert for attempts to compromise identity providers like Okta, since attackers may target centralized login systems.

Red flags to watch for

  • Unexpected helpdesk call about a “mandatory” migration
  • Caller reaches out via personal phone number
  • Pressure to complete a device-code sign-in that grants access
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Helix hit Uber Freight and claims they stole nearly one million files from mailboxes and OneDrive. The entry point? A fake IT helpdesk call. Google links this to a group called UNC6671. They call employees on their personal phones, pose as IT running a 'mandatory security migration,' then walk you through a device code login to grab your Microsoft 365 session. Here’s the trap: that device code doesn’t just log you in, it hands over an authenticated session. From there, they can siphon mailboxes, OneDrive, even hit Okta and other cloud repositories without ever knowing your password. If anyone calls you about a 'mandatory migration' and wants you to enter a device code, hang up and contact IT through our official helpdesk channel yourself. One call from you can stop a million-file breach.

Similar attacks

Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
UNC6671 Rebrands, Runs IT Helpdesk Vishing

UNC6671 Rebrands, Runs IT Helpdesk Vishing

Google Threat Intelligence reports that extortion group UNC6671 (formerly branded “BlackFile”) is calling employees while posing as IT helpdesk staff and pushing “urgent security migrations.” Victims are lured to spoofed login pages to capture passwords and MFA tokens, enabling Microsoft 365/Okta…

August 7, 2026
Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026