Firewall Daily

U-Haul Confirms Data Breach, Customer Information Leaked

Amerco, the parent company of moving and storage rental U-Haul, recently disclosed a data breach due to an unauthorized identity having access to an undefined number of rental contracts.  Although it is unclear how many clients were impacted by the attack, their credit card information, the company claimed, appears safe.

According to a report by the company, the offender had access to the clients’ names, driver’s licenses (and the data on them, such as physical addresses and dates of birth), and state identification numbers.

U-Haul data breach explained

On September 9, 2022, U-Haul notified the affected customers about a possible data breach. In the notice letter, the American moving supplier stated that two unique passwords were used to access customers’ contract details. A search tool was also used to access contracts for U-Haul customers.

We detected a compromise of two unique passwords that were used to access a customer contract search tool that allows access to rental contracts for U-Haul customers. The search tool cannot access payment card information; no credit card information was accessed or acquired,” the report stated.

With the aid of outside cybersecurity specialists, the company launched an investigation, concluding that some rental contracts were accessed between November 5, 2021, and April 5, 2022. Evidently, on September 7, the investigation concluded, and a few days later, the notices were sent to affected customers.

However, despite the involvement of cybersecurity specialists, the data breach notice and the complaint didn’t explain how the passwords that allowed access to the search tool’s functionality were hacked. The company claims that no financial information, payment processing, or email systems were impacted, and U-Haul continues to follow standard working procedures. Its parent company, Amerco, also ensured customers that the event did not majorly affect its business and financial position.

U-Haul will strengthen its security protocols

Post the incident, U-Haul stated that it would enhance the security measures and add more security controls and protections against these types of attacks. It also claimed to add new standards for the Search features that were the main target of the threat actor.

Moreover, the company aims to provide affected customers with complimentary identity theft protection services through Equifax for an entire year. The data protection service seems to be made more than ten months after the breach incident and five months after it was reportedly discovered.

The customer information obtained or breached could have been utilized inappropriately. According to reports, at least one class action law firm is urging those who may have been impacted to contact them to discuss “possible legal remedies.”

Avantika

Avantika Chopra is the Associate Editor at The Cyber Express, where she brings over seven years of in-depth journalism experience to the forefront of cybersecurity news. With a keen eye for detail and a passion for the latest in cyber defense technologies, Avantika has been instrumental in reporting and shaping the narrative around digital security trends and threats. Her work emphasizes the importance of understanding cybersecurity not just as a technical field, but as a critical element of modern governance and personal safety. When she's not dissecting the latest cyber threats, you might find her caring for her garden or planning her next adventure.

Recent Posts

The Cyber Express Weekly Roundup: AI Disruption, Regulatory Pressure, and the Evolving Cyber Threat Landscape

AI fraud, deepfake probes, SME cyber warnings, and ransomware cases highlight rising global risks in this week’s Cyber Express roundup.

2 days ago

French National Bank Authority Breach Exposed 1.2 Million Accounts

French national bank authority confirmed a major data breach affecting 1.2 million bank accounts after a malicious actor stole credentials…

2 days ago

What Big Tech Leaders Said On AI’s Future at India AI Impact Summit 2026

The real success of AI will not only depend on how powerful the technology becomes, but on how safely, fairly,…

2 days ago

Two Petabytes Worth Data of Israeli’s Siphoned, Says Cyber Head

Israel data breach totals two petabytes, with phishing up 35% and cyber influence attacks rising 170%, says Yossi Karadi.

2 days ago

Cyberattack Forces Clinic Closures, Surgery Cancellations at University of Mississippi Medical Center

The UMMC cyberattack halted surgeries, closed clinics statewide and triggered a federal probe into potential patient data exposure.

2 days ago

First Android Malware Weaponizes Gemini AI to Evade Detection, Maintain Persistence

ESET researchers discovered PromptSpy, the first known Android malware to integrate generative AI directly into its execution flow, marking a…

3 days ago

This website uses cookies. By continuing to use this website you are giving consent to cookies being used.

Read More