Helix хакерын бүлэглэл логистикийн компанийн мэдээллийн санд нэвтэрч, хувь хүний болон байгууллагын нууц мэдээллийг олзворлосон гэж мэдэгджээ.
Uber Freight компанийн төлөөлөгч мэдээлснээр, тус компанийн үйл ажиллагаа хэвийн үргэлжилж байгаа бөгөөд одоогоор системийн доголдол гараагүй байна. Гэсэн хэдий ч Helix нэртэй хакерын бүлэглэл тус компанийн цахим шуудан, үүлэн сан (cloud storage), дансны тооцоо болон тээвэрлэлтийн баримт бичгүүдийг хулгайлсан гэж өөрсдийн мэдээллийн сайтад нийтэлжээ.
Google-ийн аюулгүй байдлын шинжээчдийн тодорхойлсноор Helix бүлэглэл нь UNC6671 нэртэй томоохон сүлжээний нэг хэсэг юм. Тэд мэдээллийн технологийн туслах төвүүд рүү утасдаж, нууц үг шинэчлэх хүсэлт гаргах замаар нийгмийн инженерчлэлийн аргаар байгууллагын системд нэвтэрдэг байна.
Дээрх хакерууд нь санхүү болон тээврийн салбарын компаниудыг голчлон онилдог бөгөөд олзворлосон мэдээллээ олон нийтэд дэлгэнэ хэмээн сүрдүүлж, мөнгө нэхэх замаар ашгаа олдог. Google-ийн судалгаагаар тус бүлэглэл энэ оны нэгдүгээр сараас тавдугаар сарын хооронд хамгийн багадаа 10.6 сая ам.долларыг биткойноор хүлээн авсан нь тогтоогджээ.
Дэлгэрэнгүйг эх сурвалжаас харах
↓Эх сурвалжийг нээх ↓
A hacking and extortion gang has taken credit for a cyberattack and data breach at Uber Freight, the ridesharing giant’s logistics subsidiary.
A spokesperson for Uber Freight told Reuters, which first reported the incident, that there was no effect on its business operations and that its systems were running normally. (The company did not immediately respond to TechCrunch’s questions about the incident.)
The shipping company is the latest victim in a spate of hacks in recent weeks conducted by the Helix hacking group, which has targeted transportation companies, financial giants, and private equity firms throughout the year. The hackers are known for targeting companies and exfiltrating large amounts of data from their cloud environments, which they then threaten to publish if the victim companies do not pay a ransom.
In a post on its data leak site, which it uses to host the stolen files, the Helix hackers claim to have taken mailboxes, cloud storage drives, files relating to accounts payable, and dispatch documents from Uber Freight.
Some of the files seen by TechCrunch appear to show email correspondence between Uber Freight and several of its customers. TechCrunch could not immediately verify the authenticity of the files, which appeared to be dated around mid-June.
Uber Freight has not yet said if it received any correspondence from the hackers, or if it paid the hackers a ransom.
Google said earlier this week that the Helix hacking group is part of a wider umbrella collective of hackers that it tracks as UNC6671. The gang relies on social engineering tactics, such as voice phishing, a tactic that involves calling IT helpdesks and requesting the reset of employee passwords. Security researchers have long warned that these attacks, while crude and rudimentary, are highly effective at tricking humans into granting access to sensitive systems.
In its blog post, Google said a review of the gang’s bitcoin wallets shows it has made at least $10.6 million in ransom payments between January and May this year.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

