U-Haul says hacker accessed customer records using stolen creds

  • February 23, 2024
  •  
  • 09:16 AM
  •  
  • 0

U-Haul

U-Haul has started informing customers that a hacker used stolen account credentials to access an internal system for dealers and team members to track customer reservations.

The breach exposed customer records that include personal information but payment details have not been impacted.

U-Haul is an American company that rents moving equipment and storage space for ‘do-it-yourself’ customer needs. It offers trucks, trailers, and other equipment and services for moving household goods.

The firm has been operational since 1945, has a staff of 19,500, and has an annual revenue of over $4.5 billion.

Yesterday, U-Haul began emailing customers whose data was accessed without authorization in the cyberattack.

“U-Haul learned on December 5, 2023, that legitimate credentials were used by an unauthorized party to access a system U-Haul Dealers and Team Members use to track customer reservations and view customer records,” - U-Haul

“The investigation identified specific customer records that were accessed, including one of your records,” the company says in the notification to customers.

The data types that have been exposed in these customer records include full names, dates of birth, and driver’s license numbers.

U-Haul clarified that the breached system is not part of their payment system, so hackers could not access payment card data.

The company says it has reset passwords for all affected accounts as a precaution and implemented additional security safeguards and controls to prevent similar incidents from occurring in the future.

Recipients of the data breach notification will receive a one-year identity theft protection service with instructions on how to enroll enclosed in the letters.

U-Haul has not determined how many customers have been exposed in this case.

BleepingComputer has contacted U-Haul to learn more about the data breach and its scope of impact, but a comment wasn’t immediately available. Also, the company’s website was offline at the time of writing this.

In September 2022, U-Haul disclosed another data breach, saying that attackers had accessed customer rental contracts between November 2021 and April 2022.

In that case too, the hackers used two compromised account credentials to access U-Haul’s internal portal.

Αναζήτηση
Κατηγορίες
Διαβάζω περισσότερα
Fake Leather wallet app on Apple App Store is a crypto drainer
March 11, 2024   10:54 AM   0 The developers of the Leather...
από AFFA 2024-03-11 16:56:34 0 114
UK says AI will empower ransomware over the next two years
January 24, 2024   11:56 AM   0 The United Kingdom's National...
από AFFA 2024-01-24 18:23:38 0 210
How the FBI seized BlackCat (ALPHV) ransomware’s servers
December 19, 2023   12:27 PM   0 An unsealed FBI search warrant...
από AFFA 2023-12-19 21:14:13 0 320
Windows 10 KB5035845 update released with 9 new changes, fixes
Microsoft has released the KB5035845 cumulative update for Windows 10 21H2 and Windows 10 22H2,...
από AFFA 2024-03-13 15:59:19 0 116
Windows 11 KB5035942 update enables Moment 5 features for everyone
March 26, 2024   06:28 PM   0 Microsoft has released the March...
από AFFA 2024-03-27 14:53:17 0 91