HackingData ExfiltratedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASICMediumContained
Yellow Corporation and its affiliated debtors and debtors-in-possession under their jointly administered chapter 11 cases (Case No. 23-11069 (Bankr. D. Del. (CTG))
bd_599e40dc7dee1087 · schema v1 · pii pii-v1
Full breach record for Yellow Corporation and its affiliated debtors and debtors-in-possession under their jointly administered chapter 11 cases (Case No. 23-11069 (Bankr. D. Del. (CTG)) →Yellow Corporation identified suspicious activity and unauthorized exfiltration of files on March 27, 2025. The incident involved former employee data including names, SSNs, financial account numbers, and medical information. Systems were restored from backups and additional safeguards implemented. No specific count of affected individuals was disclosed.
California clockDiscovered Mar 27, 2025 → Notified Jun 26, 2026456d ✗ CA 60-day late15 months discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-625494
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2026
- Raw hash
- b547ccd6fdf911ab12798808ad9b5759979213d110384bfd50d1c40f5f6e1d74
Reporting entity
- Name
- Yellow Corporation and its affiliated debtors and debtors-in-possession under their jointly administered chapter 11 cases (Case No. 23-11069 (Bankr. D. Del. (CTG))norm: yellow corporation and its affiliated debtors and debtors in possession under their jointly administered chapter 11 cases case no 23 11069 bankr d del ctg
- Domain
- www.myyellow.com
Victim entity
- Name
- Yellow Corporation and its affiliated debtors and debtors-in-possession under their jointly administered chapter 11 cases (Case No. 23-11069 (Bankr. D. Del. (CTG))norm: yellow corporation and its affiliated debtors and debtors in possession under their jointly administered chapter 11 cases case no 23 11069 bankr d del ctg
- Domain
- www.myyellow.com
Incident
- Discovered
- Mar 27, 2025
- Materiality determined
- —
- Notification sent
- Jun 26, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPHIHEALTH_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notifying relevant regulators where necessary
Compliance
- Time to disclose
- 15 months(456 days from discovery to filing)
- Compliance flags
- CA 60-day late · 456dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 27, 2025→ Notified: Jun 26, 2026456d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Jun 26, 2026→ AG copy submitted: Jun 26, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.