HackingStolen CredentialsTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
U-Haul International, Inc.
bd_eaed14df91a513cc · schema v1 · pii pii-v1
Full breach record for U-Haul International, Inc. →U-Haul International notified consumers of a December 5, 2023 incident where unauthorized parties used legitimate credentials to access a customer reservation system. Affected data included names, dates of birth, and driver's license numbers. No payment card data was compromised. U-Haul engaged a cybersecurity firm, reset passwords, and offered one year of Experian IdentityWorks.
Vermont clock✗ VT AG >45 bday11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1819513f52a2ee75California State AGfiled 2024-02-22Candidate
- bd_21049826afecbe0cNew Hampshire State AGfiled 2024-02-22Verified
- bd_700fc89b40abfc60Indiana State AGfiled 2024-02-22Verified
- bd_a4861d7cc89712beOregon State AGfiled 2024-02-22Verified
Show 2 more filings ↓Show fewer ↑
- bd_bc9049d2d7ad3937Washington State AGfiled 2024-02-22Verified
- bd_bd22cab7f871d721Maine State AGfiled 2024-02-22Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-02-22-u-haul-international-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 22, 2024
- Raw hash
- 940f6d187af448c7739535cc29349d8d9961a7eeadc593fc1fff2df970229766
Reporting entity
- Name
- U-Haul International, Inc.norm: u haul
Victim entity
- Name
- U-Haul International, Inc.norm: u haul
Incident
- Discovered
- Dec 5, 2023
- Materiality determined
- —
- Notification sent
- Feb 22, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.