HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
U-Haul International, Inc.
bd_b8082447aed60375 · schema v1 · pii pii-v1
Full breach record for U-Haul International, Inc. →U-Haul International, Inc. notified the New Hampshire Attorney General of a cybersecurity incident affecting 7,948 NH residents. Unauthorized parties used compromised credentials to access a customer contract search tool between November 5, 2021, and April 5, 2022. The accessed data included names and driver's license/state ID numbers. U-Haul engaged a cybersecurity firm, secured the account, and provided one year of credit monitoring to affected individuals.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1ef6523a576cc946Delaware State AGfiled 2022-09-09(3d gap)Candidate
- bd_45c94d5ea35f726dWashington State AGfiled 2022-09-09(3d gap)Verified
- bd_939d4740c11bcd9eOregon State AGfiled 2022-09-09(3d gap)Verified
- bd_9476e19e00a93d97California State AGfiled 2022-09-09(3d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 3d gap
- bd_c49cf3b69da05aabMaine State AGfiled 2022-09-09(3d gap)Verified
- bd_f7f4e0374a574f48Montana State AGfiled 2022-09-09(3d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/uhaul-international-20220912.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 12, 2022
- Raw hash
- e1e0dacdb0510457e2639b125a50ad3a12ad633ea58ee10f10ebfa2a572fbcdb
Reporting entity
- Name
- Baker & Hostetler LLP (on behalf of U-Haul International, Inc.)norm: baker hostetler llp on behalf of u haul
Victim entity
- Name
- U-Haul International, Inc.norm: u haul
Incident
- Discovered
- Jul 12, 2022
- Materiality determined
- —
- Notification sent
- Sep 9, 2022
- Affected individuals
- 7,948
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.