U-Haul International, Inc.
ent_019e233821edea24c53b16512e0f9aeb
Disclosures
24
State AG · 13 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
2,195,831
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- U-Haul International, Inc.
- Normalized
- u haul— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300AFY4WTM1ZIZG91
- SEC EDGAR CIK
- 0000004457
- Domain
- None on record
Disclosure history (24)newest first
- California State AGas victim2024-02-22
U-Haul International disclosed that an unauthorized party used legitimate credentials to access a system used by dealers and team members to track customer reservations. The incident occurred between July 20 and October 2, 2023, and was discovered on December 5, 2023. Affected data included names, dates of birth, and driver's license numbers. U-Haul engaged a cybersecurity firm, changed passwords, and is offering one year of identity protection services.
- New Hampshire State AGas victim2024-02-22
U-Haul International filed a breach notification with the New Hampshire Attorney General regarding an incident affecting customer data. The notification letter offers one year of Experian IdentityWorks services, indicating identity theft risk involving personal information. Specific details on the attack vector, dates, or number of affected individuals are not present in the provided attachment text.
- Massachusetts State AGas victim2024-02-22
U-Haul International, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-02-22. 1,130 Massachusetts residents were affected.
- Indiana State AGas victim2024-02-22
U-Haul International, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-07-20 and was reported on 2024-02-22. 968 Indiana residents were affected. 57,177 individuals affected in total.
- Oregon State AGas victim2024-02-22
U-Haul International, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-02-22. The breach occurred during 7/20/2023 - 10/2/2023. The breach was discovered on 12/5/2023. 57,177 individuals were affected. Notice was sent on 2/22/2024.
- Washington State AGas victim2024-02-22
U-Haul International, Inc. notified Washington AG that unauthorized parties used legitimate credentials to access a customer reservation system between July 20 and October 2, 2023. The breach exposed names, DOBs, and driver's license numbers of 16,460 Washington residents. U-Haul engaged forensic investigators, reset passwords, and offered one year of credit monitoring.
- Maine State AGas victim2024-02-22
U-Haul International, Inc. experienced an external system breach where an unauthorized party gained access to customer information. The compromised data includes names and driver's license or non-driver identification card numbers. The breach occurred between July 20, 2023, and October 2, 2023, and was discovered on December 5, 2023. Affected individuals were notified on February 22, 2024, and offered one year of credit monitoring and identity theft protection services from Experian.
- Vermont State AGas victim2024-02-22
U-Haul International notified consumers of a December 5, 2023 incident where unauthorized parties used legitimate credentials to access a customer reservation system. Affected data included names, dates of birth, and driver's license numbers. No payment card data was compromised. U-Haul engaged a cybersecurity firm, reset passwords, and offered one year of Experian IdentityWorks.
- Illinois State AGas victim2024-02-01
U-HAUL INTERNATIONAL filed a data-breach notice with the Illinois Attorney General in February 2024 (case 24-02-208). The register records the breach as discovered on December 5, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2023-12-01
U-Haul International, Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-12-01. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2022-09-12
U-Haul International, Inc. notified the New Hampshire Attorney General of a cybersecurity incident affecting 7,948 NH residents. Unauthorized parties used compromised credentials to access a customer contract search tool between November 5, 2021, and April 5, 2022. The accessed data included names and driver's license/state ID numbers. U-Haul engaged a cybersecurity firm, secured the account, and provided one year of credit monitoring to affected individuals.
- South Carolina State AGas victim2022-09-09
U-Haul International, Inc. notified customers that an unauthorized person accessed the customer contract search tool using compromised passwords. The incident involved access to names and driver's license/state ID numbers between November 5, 2021, and April 5, 2022. U-Haul engaged cybersecurity experts, reset passwords, and offered one year of Equifax identity theft protection.
- Delaware State AGas victim2022-09-09
U-Haul International, Inc. disclosed a cybersecurity incident in Delaware involving unauthorized access to a customer contract search tool. Between November 5, 2021, and April 5, 2022, an unauthorized party used compromised credentials to access rental contracts for 4,903 Delaware residents. The accessed data included names and driver's license numbers. No financial or payment card information was compromised. U-Haul engaged a cybersecurity firm, secured the account, and offered one year of free credit monitoring and identity theft protection services through Equifax.
- Massachusetts State AGas victim2022-09-09
U-Haul International, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-09-09. 37,202 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2022-09-09
U-Haul International, Inc. reported unauthorized access to a customer contract search tool using compromised credentials between Nov 2021 and Apr 2022. Detected July 12, 2022. 61,770 Washington residents affected; data included names, DOBs, and driver's licenses. U-Haul engaged forensic experts, reset credentials, and offered 1-year credit monitoring.
- Hawaii State AGas victim2022-09-09
U-Haul International, Inc. notified customers that an unauthorized person accessed the customer contract search tool using compromised passwords. The incident involved access to customer names and driver's license/state ID numbers between November 2021 and April 2022. U-Haul engaged cybersecurity experts, reset passwords, and offered one year of Equifax identity theft protection.
- Oregon State AGas victim2022-09-09
U-Haul International, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2022-09-09. The breach occurred during 11/4/2021 - 4/5/2022. The breach was discovered on 9/7/2022. 2,195,831 individuals were affected. Notice was sent on 9/9/2022.
- California State AGas victim2022-09-09
U-Haul International, Inc. disclosed that an unauthorized person accessed a customer contract search tool using compromised passwords between November 5, 2021, and April 5, 2022. The incident was detected on August 1, 2022. Affected data includes names and driver's license or state identification numbers. No payment card information was accessed. U-Haul changed passwords, engaged cybersecurity experts, and is offering one year of identity theft protection through Equifax.
- Indiana State AGas victim2022-09-09
U-Haul International, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-11-05 and was reported on 2022-09-09. 36,557 Indiana residents were affected. 2,195,831 individuals affected in total.
- Maine State AGas victim2022-09-09
U-Haul International, Inc. reported a data breach impacting 7,181 Maine residents. The breach, described as an external system hacking incident, occurred between November 5, 2021, and April 5, 2022, and was discovered on September 7, 2022. The compromised information includes names combined with driver's license or non-driver identification card numbers. U-Haul provided written notification to affected individuals on September 9, 2022, and offered one year of credit monitoring and identity theft protection services through Equifax.
- Montana State AGas victim2022-09-09
U-Haul International, Inc. notified customers that unauthorized access to a customer contract search tool occurred between November 2021 and April 2022. Compromised credentials allowed access to rental contracts containing names and driver's license/state ID numbers. No payment card data was accessed. U-Haul changed passwords, engaged cybersecurity experts, and offered one year of Equifax identity theft protection.
- Massachusetts State AGas reporting2017-12-12
U-Haul Co. of California reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-12-12. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas reporting2017-12-12
U-Haul Co. of California notified the NH Attorney General of a malware incident at an independent dealer, Solo Tire, affecting one NH resident. Data accessed included PII, driver's license, and payment card info. Incident occurred Jan-Oct 2017. Notifications sent Dec 12, 2017.
- California State AGas reporting2017-12-12
A computer workstation at Solo Tire, an independent U-Haul dealer in Orange, CA, was infected with malware targeting payment card data. Customers who reserved or rented equipment from January 10 to October 16, 2017 may have had name, address, phone, email, driver's license, birth date, and payment card details compromised. The incident was contained to the Solo Tire location.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of U-Haul International, Inc. — not by U-Haul International, Inc. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Massachusetts State AGvia Oxford Life Insurance Company2025-05-14
Oxford Life Insurance Company reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-05-14. 300 Massachusetts residents were affected.
- Vermont State AGvia Oxford Life Insurance Company2025-05-14
Oxford Life Insurance Company notified consumers that an unauthorized person accessed its IT network for approximately one hour on February 20, 2025, and copied files. The company contained the activity and engaged a third-party cybersecurity firm. A review completed on April 17, 2025, determined that the files contained personal information. The company is offering one year of complimentary identity protection services through Experian IdentityWorks and has implemented additional security safeguards.
- Oregon State AGvia Oxford Life Insurance Company2025-05-13
Oxford Life Insurance Company reported a data breach to the Oregon Attorney General. The breach was reported on 2025-05-13. The breach occurred during 2/20/2025 - 2/20/2025. The breach was discovered on 4/18/2025. 25,659 individuals were affected. Notice was sent on 5/13/2025.
- New Hampshire State AGvia Oxford Life Insurance Company2025-05-13
Oxford Life Insurance Company notified the NH Attorney General of a cybersecurity event on Feb 20, 2025. An external threat actor used social engineering (impersonating a collections company) to gain unauthorized access to an employee's computer and Oxford's network for approximately one hour. The actor copied files containing personal information of policyholders, claimants, and agents in New Hampshire. The incident did not involve ransomware. Oxford engaged a third-party forensic firm, contained the activity, and is offering identity restoration services.
- California State AGvia Oxford Life Insurance Company2025-05-13
Oxford Life Insurance Company reported that an unauthorized person accessed its IT network for approximately one hour on February 20, 2025, and copied files. The company engaged a third-party cybersecurity firm to investigate and contained the activity. A review completed on April 17, 2025, determined that personal information was involved. The company is offering one year of complimentary identity protection services to affected individuals.
- Maine State AGvia Oxford Life Insurance Company2025-05-13
Oxford Life Insurance Company reported a social engineering attack in Maine affecting 30 residents. The breach occurred on Feb 20, 2025, when an attacker impersonated a collections company to gain network access. Data exposed included names and SSNs. Notifications were sent on May 13, 2025, with credit monitoring offered.
- Indiana State AGvia Oxford Life Insurance Company2025-05-13
Oxford Life Insurance Company reported a data breach to the Indiana Attorney General. The breach occurred on 2025-02-20 and was reported on 2025-05-13. 797 Indiana residents were affected. 25,659 individuals affected in total.
- Iowa State AGvia Oxford Life Insurance Company2025-05-13
Oxford Life Insurance Company notified the Iowa AG of a cybersecurity incident on May 13, 2025. On Feb 20, 2025, a social engineering attack allowed an unauthorized actor to access the network for one hour and copy files. Affected data included names, SSNs, and financial account numbers for 511 Iowa residents. Oxford engaged forensic investigators, contained the breach, and offered one year of credit monitoring.
- Nebraska State AGvia Oxford Life Insurance Company2025-05-13
Oxford Life Insurance Company experienced a phishing incident on February 20, 2025, where an unauthorized actor accessed its IT network for approximately one hour and copied files containing names and Social Security numbers of 419 Nebraska residents. Oxford contained the breach, engaged forensic investigators, notified affected individuals on May 13, 2025, and offered one year of credit monitoring through Experian.
- Illinois State AGvia Oxford Life Insurance Company2025-05-01
OXFORD LIFE INSURANCE COMPANY filed a data-breach notice with the Illinois Attorney General in May 2025 (case 25-05-151). The register records the breach as discovered on April 18, 2025. Personal information types reported: drivers license, financial account number, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.