HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
U-Haul International, Inc.
bd_1ef6523a576cc946 · schema v1 · pii pii-v1
Full breach record for U-Haul International, Inc. →U-Haul International, Inc. disclosed a cybersecurity incident in Delaware involving unauthorized access to a customer contract search tool. Between November 5, 2021, and April 5, 2022, an unauthorized party used compromised credentials to access rental contracts for 4,903 Delaware residents. The accessed data included names and driver's license numbers. No financial or payment card information was compromised. U-Haul engaged a cybersecurity firm, secured the account, and offered one year of free credit monitoring and identity theft protection services through Equifax.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_45c94d5ea35f726dWashington State AGfiled 2022-09-09Verified
- bd_939d4740c11bcd9eOregon State AGfiled 2022-09-09Verified
- bd_9476e19e00a93d97California State AGfiled 2022-09-09Verified
- bd_c49cf3b69da05aabMaine State AGfiled 2022-09-09Verified
Show 2 more filings ↓Show fewer ↑up to 3d gap
- bd_f7f4e0374a574f48Montana State AGfiled 2022-09-09Verified by operator
- bd_b8082447aed60375New Hampshire State AGfiled 2022-09-12(3d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/09/U-Haul-Delaware-Attachment.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 9, 2022
- Raw hash
- 737e0fef0578fcc057e1c62e61d375653bbd5ac641911ebaa47912d0f900e857
Reporting entity
- Name
- U-Haul International, Inc.norm: u haul
Victim entity
- Name
- U-Haul International, Inc.norm: u haul
Incident
- Discovered
- Jul 12, 2022
- Materiality determined
- —
- Notification sent
- Sep 9, 2022
- Affected individuals
- 4,903
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(59 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.