HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
U-Haul International, Inc.
bd_1819513f52a2ee75 · schema v1 · pii pii-v1
Full breach record for U-Haul International, Inc. →U-Haul International disclosed that an unauthorized party used legitimate credentials to access a system used by dealers and team members to track customer reservations. The incident occurred between July 20 and October 2, 2023, and was discovered on December 5, 2023. Affected data included names, dates of birth, and driver's license numbers. U-Haul engaged a cybersecurity firm, changed passwords, and is offering one year of identity protection services.
California clockDiscovered Dec 5, 2023 → Notified Feb 22, 202479d ✗ CA 60-day late11 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_21049826afecbe0cNew Hampshire State AGfiled 2024-02-22Verified
- bd_700fc89b40abfc60Indiana State AGfiled 2024-02-22Verified
- bd_a4861d7cc89712beOregon State AGfiled 2024-02-22Verified
- bd_bc9049d2d7ad3937Washington State AGfiled 2024-02-22Verified
Show 2 more filings ↓Show fewer ↑
- bd_bd22cab7f871d721Maine State AGfiled 2024-02-22Verified
- bd_eaed14df91a513ccVermont State AGfiled 2024-02-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-581372
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 22, 2024
- Raw hash
- cd3e7846473b3eee3dd1953c8cc9ff41179757eadf24c95533d98e3fd7fb08d6
Reporting entity
- Name
- U-Haul International, Inc.norm: u haul
Victim entity
- Name
- U-Haul International, Inc.norm: u haul
Incident
- Discovered
- Dec 5, 2023
- Materiality determined
- —
- Notification sent
- Feb 22, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- CA 60-day late · 79d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 5, 2023→ Notified: Feb 22, 202479d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.