YELLOW CORPORATION
bd_1b4409988dd125be · schema v1 · pii pii-v1
Full breach record for YELLOW CORPORATION →Yellow Corporation, a transportation/logistics company, notified individuals of a data security event occurring on March 27, 2025. Unauthorized access resulted in the exfiltration of files containing names, SSNs, driver's licenses, financial account numbers, payment card numbers, and medical/health insurance information. The majority of affected records belong to former employees. Yellow engaged third-party cybersecurity specialists, took systems offline, restored from backups, and implemented additional technical safeguards. No specific count of affected individuals was disclosed due to the historical nature of the data and inability to verify contact information.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_02ca38c55dca0157New Hampshire State AGfiled 2026-06-26(25d gap)Verified
- bd_25143fe3a8be2bc1Indiana State AGfiled 2026-06-26(25d gap)Verified
- bd_c2e30e440f2ff96cSouth Carolina State AGfiled 2026-06-26(25d gap)Candidate
- bd_cd729262a7431f71Oregon State AGfiled 2026-07-08(37d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1038-yellow-corporation/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- 72708cfebc6ff89fb96b9aa00f570cdf67f6e5180fe73d2d3701dde06e7e4f0e
Reporting entity
- Name
- YELLOW CORPORATIONnorm: yellow
Victim entity
- Name
- YELLOW CORPORATIONnorm: yellow
Incident
- Discovered
- Mar 27, 2025
- Materiality determined
- —
- Notification sent
- Jun 26, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notifying relevant regulators where necessary
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 months(431 days from discovery to filing)
- Compliance flags
- MA AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.