U-Haul International, Inc.
ent_019e233821edea24c53b16512e0f9aeb
Disclosures
15
State AG · 9 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
2,195,831
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- U-Haul International, Inc.
- Normalized
- u haul— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300AFY4WTM1ZIZG91
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (15)newest first
- 🐻California State AGas victim2024-02-22
U-Haul International disclosed that an unauthorized party used legitimate credentials to access a system used by dealers and team members to track customer reservations. The incident occurred between July 20 and October 2, 2023, and was discovered on December 5, 2023. Affected data included names, dates of birth, and driver's license numbers. U-Haul engaged a cybersecurity firm, changed passwords, and is offering one year of identity protection services.
- ⛰️New Hampshire State AGas victim2024-02-22
U-Haul International filed a breach notification with the New Hampshire Attorney General regarding an incident affecting customer data. The notification letter offers one year of Experian IdentityWorks services, indicating identity theft risk involving personal information. Specific details on the attack vector, dates, or number of affected individuals are not present in the provided attachment text.
- 🏎️Indiana State AGas victim2024-02-22
U-Haul International, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-07-20 and was reported on 2024-02-22. 968 Indiana residents were affected. 57,177 individuals affected in total.
- 🦫Oregon State AGas victim2024-02-22
U-Haul International, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-02-22. The breach occurred during 7/20/2023 - 10/2/2023. The breach was discovered on 12/5/2023. 57,177 individuals were affected. Notice was sent on 2/22/2024.
- 🌲Washington State AGas victim2024-02-22
U-Haul International, Inc., a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-12-05 and filed notice on 2024-02-22. 16,460 Washington residents were affected. 79 days elapsed between awareness and notification. 138 days to identify the breach. 0 days to contain the breach.
- 🦞Maine State AGas victim2024-02-22
U-Haul International, Inc. experienced an external system breach where an unauthorized party gained access to customer information. The compromised data includes names and driver's license or non-driver identification card numbers. The breach occurred between July 20, 2023, and October 2, 2023, and was discovered on December 5, 2023. Affected individuals were notified on February 22, 2024, and offered one year of credit monitoring and identity theft protection services from Experian.
- 🍁Vermont State AGas victim2024-02-22
U-Haul International notified consumers of a December 5, 2023 incident where unauthorized parties used legitimate credentials to access a customer reservation system. Affected data included names, dates of birth, and driver's license numbers. No payment card data was compromised. U-Haul engaged a cybersecurity firm, reset passwords, and offered one year of Experian IdentityWorks.
- ⛰️New Hampshire State AGas victim2022-09-12
U-Haul International, Inc. notified the New Hampshire Attorney General of a cybersecurity incident affecting 7,948 NH residents. Unauthorized parties used compromised credentials to access a customer contract search tool between November 5, 2021, and April 5, 2022. The accessed data included names and driver's license/state ID numbers. U-Haul engaged a cybersecurity firm, secured the account, and provided one year of credit monitoring to affected individuals.
- 💎Delaware State AGas victim2022-09-09
U-Haul International, Inc. disclosed a cybersecurity incident in Delaware involving unauthorized access to a customer contract search tool. Between November 5, 2021, and April 5, 2022, an unauthorized party used compromised credentials to access rental contracts for 4,903 Delaware residents. The accessed data included names and driver's license numbers. No financial or payment card information was compromised. U-Haul engaged a cybersecurity firm, secured the account, and offered one year of free credit monitoring and identity theft protection services through Equifax.
- 🌲Washington State AGas victim2022-09-09
U-Haul International, Inc., a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2022-09-07 and filed notice on 2022-09-09. 61,770 Washington residents were affected. 2 days elapsed between awareness and notification. 306 days to identify the breach. 0 days to contain the breach.
- 🦫Oregon State AGas victim2022-09-09
U-Haul International, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2022-09-09. The breach occurred during 11/4/2021 - 4/5/2022. The breach was discovered on 9/7/2022. 2,195,831 individuals were affected. Notice was sent on 9/9/2022.
- 🐻California State AGas victim2022-09-09
U-Haul International, Inc. reported a data breach affecting California residents. Between November 5, 2021, and April 5, 2022, an unauthorized individual accessed a customer contract search tool using compromised passwords. The breach exposed customer names and driver's license or state identification numbers. No payment card or financial data was accessed. U-Haul engaged cybersecurity experts, reset credentials, and offered one year of Equifax identity theft protection to affected individuals.
- 🦞Maine State AGas victim2022-09-09
U-Haul International, Inc. reported a data breach impacting 7,181 Maine residents. The breach, described as an external system hacking incident, occurred between November 5, 2021, and April 5, 2022, and was discovered on September 7, 2022. The compromised information includes names combined with driver's license or non-driver identification card numbers. U-Haul provided written notification to affected individuals on September 9, 2022, and offered one year of credit monitoring and identity theft protection services through Equifax.
- 🦬Montana State AGas victim2022-09-09
U-Haul International, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2022-09-09. The breach occurred from 11/5/2021 to 4/5/2022. 5,568 Montana residents were affected.
- 🐻California State AGas reporting2017-12-12
A computer workstation at Solo Tire, an independent U-Haul dealer in Orange, CA, was infected with malware targeting payment card data. Customers who reserved or rented equipment from January 10 to October 16, 2017 may have had name, address, phone, email, driver's license, birth date, and payment card details compromised. The incident was contained to the Solo Tire location.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of U-Haul International, Inc. — not by U-Haul International, Inc. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.