HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICPHIMediumContained
YELLOW CORPORATION
bd_c2e30e440f2ff96c · schema v1 · pii pii-v1
Full breach record for YELLOW CORPORATION →Yellow Corporation, a transportation/logistics company, disclosed a cybersecurity incident occurring on March 27, 2025, where unauthorized actors accessed and exfiltrated files containing PII, PHI, and financial data. The breach primarily affected former employees. Yellow engaged third-party cybersecurity specialists, took systems offline, restored from backups, and implemented additional technical safeguards. Notification was issued on June 26, 2026, to residents in multiple states including South Carolina, New York, and Maryland.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_02ca38c55dca0157New Hampshire State AGfiled 2026-06-26Verified
- bd_25143fe3a8be2bc1Indiana State AGfiled 2026-06-26Verified
- bd_cd729262a7431f71Oregon State AGfiled 2026-07-08(12d gap)Verified
- bd_1b4409988dd125beMassachusetts State AGfiled 2026-06-01(25d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2026/Consumer%20Letter%20-%20Yellow%20Corporation.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2026
- Raw hash
- 257abeab8ddd791e48e057f203c84f1c4ef0676652209d5e8c6bc0589c6d492c
Reporting entity
- Name
- YELLOW CORPORATIONnorm: yellow
Victim entity
- Name
- YELLOW CORPORATIONnorm: yellow
Incident
- Discovered
- Mar 27, 2025
- Materiality determined
- —
- Notification sent
- Jun 26, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notifying relevant regulators where necessary
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 months(456 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.