Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

U-Haul Says Customer Data Accessed Using Compromised Credentials

Moving and storage giant U-Haul has started informing customers of a data breach impacting some of their personal information.

On Friday, U-Haul began sending notification letters to potentially impacted customers to inform them that compromised credentials were used to access some of their data without authorization.

Moving and storage giant U-Haul has started informing customers of a data breach impacting some of their personal information.

On Friday, U-Haul began sending notification letters to potentially impacted customers to inform them that compromised credentials were used to access some of their data without authorization.

“We detected a compromise of two unique passwords that were used to access a customer contract search tool that allows access to rental contracts for U-Haul customers,” reads a notification letter sample that U-Haul submitted to the Montana Attorney General.

The search tool, the company says, does not store payment card information, meaning that no credit card details were exposed in the incident.

However, the unauthorized party was able to access customer names, driver’s license numbers, or state identification numbers.

Between November 5, 2021, and April 5, 2022, the attackers accessed some rental contracts, the company says, without providing information on the number of impacted customers.

Advertisement. Scroll to continue reading.

“None of our financial, payment processing or U-Haul email systems were involved; the access was limited to the customer contract search tool,” U-Haul says.

SecurityWeek has emailed U-Haul for additional information on the incident and will update this article as soon as a reply arrives.

With a fleet of hundreds of thousands of trucks, trailers, and towing devices, U-Haul has a network of more than 23,000 locations across North America.

Related: Samsung US Says Customer Data Compromised in July Data Breach

Related: Ransomware Gang Claims Customer Data Stolen in TAP Air Portugal Hack

Related: Authorities Seize Online Marketplace for Stolen Credentials

Related: OneTouchPoint Discloses Data Breach Impacting Over 30 Healthcare Firms

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Doppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.

Delinea has appointed Timothy Regan as Chief Financial Officer.

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.