MalwareRetail & ConsumerTransportation & LogisticsRetailInfostealerCapture App DataData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPIIMediumContained
U-Haul Co. of California
bd_d459e5da9a3af144 · schema v1 · pii pii-v1
A computer workstation at Solo Tire, an independent U-Haul dealer in Orange, CA, was infected with malware targeting payment card data. Customers who reserved or rented equipment from January 10 to October 16, 2017 may have had name, address, phone, email, driver's license, birth date, and payment card details compromised. The incident was contained to the Solo Tire location.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-130936
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 12, 2017
- Raw hash
- 09a648020b30c437ecae8a1efccd7150c7466bd9925bceea73a1bf2be3200016
Reporting entity
- Name
- U-Haul International, Inc.norm: u haul
Victim entity
- Name
- U-Haul Co. of Californianorm: u-haul co of california
- Industry
- Retail & ConsumerllmTransportation & Logisticsllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Dec 11, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1056 Input CaptureT1005 Data from Local System
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Office of the Attorney General
- Third party
- via Solo Tire
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.