YELLOW CORPORATION
ent_019f1a00d82bb7bfe6db19eb7e0d2cdb
Disclosures
5
State AG · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
258,498
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- YELLOW CORPORATION
- Normalized
- yellow— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900SEX4UQ2WLPRC40
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 🦫Oregon State AGas victim2026-07-08
Yellow Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2026-07-08. The breach occurred during 3/22/2025 - 3/27/2025. The breach was discovered on 3/27/2025. 258,498 individuals were affected. Notice was sent on 1/1/20016/26/2026.
- ⛰️New Hampshire State AGas victim2026-06-26
Yellow Corporation notified the New Hampshire Attorney General on June 26, 2026, of a data event occurring on March 27, 2025. Unauthorized access resulted in the exfiltration of personal information, including SSNs, driver's license numbers, financial account numbers, and medical/health insurance data. The affected population consists primarily of former employees. Yellow engaged third-party cybersecurity specialists, restored systems from backups, and provided one year of credit monitoring via TransUnion. No specific individual count was disclosed.
- 🏎️Indiana State AGas victim2026-06-26
Yellow Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2025-03-27 and was reported on 2026-06-26. 6,191 Indiana residents were affected.
- 🌴South Carolina State AGas victim2026-06-26
Yellow Corporation, a transportation/logistics company, disclosed a cybersecurity incident occurring on March 27, 2025, where unauthorized actors accessed and exfiltrated files containing PII, PHI, and financial data. The breach primarily affected former employees. Yellow engaged third-party cybersecurity specialists, took systems offline, restored from backups, and implemented additional technical safeguards. Notification was issued on June 26, 2026, to residents in multiple states including South Carolina, New York, and Maryland.
- 🏛️Massachusetts State AGas victim2026-06-01
Yellow Corporation, a transportation/logistics company, notified individuals of a data security event occurring on March 27, 2025. Unauthorized access resulted in the exfiltration of files containing names, SSNs, driver's licenses, financial account numbers, payment card numbers, and medical/health insurance information. The majority of affected records belong to former employees. Yellow engaged third-party cybersecurity specialists, took systems offline, restored from backups, and implemented additional technical safeguards. No specific count of affected individuals was disclosed due to the historical nature of the data and inability to verify contact information.