U-Haul notified 67,000 customers after reservation system breach

Organization
U-Haul International, Inc.
Exploit
Credential Compromise
Industry
Vehicle Rental

U-Haul told about 67,000 customers in the United States and Canada in February 2024 that their personal details had been exposed after an unauthorised party used valid login credentials to reach an internal customer system.

The affected system is used by U-Haul dealers and staff to track reservations and view customer records. According to the company's notification, the unauthorised access ran from July 20 to October 2, 2023 and was discovered in early December 2023, which Infosecurity Magazine reported as December 5.

The exposed data was limited to names, dates of birth and driver's licence numbers. U-Haul said no payment card information was involved because the compromised system is separate from its payment network. The notification letters did not explain how the credentials were obtained.

The company said it engaged an outside cybersecurity firm to investigate, changed the passwords on the affected accounts and put additional security measures in place. Those notified were offered a complimentary one-year Experian IdentityWorks membership. Coverage at the time noted the gap of more than two months between discovery and notification, which U-Haul did not publicly account for. It was the company's second disclosed incident in under 18 months, following a September 2022 disclosure that a rental contract search tool had been accessed, affecting roughly 2.2 million customers.

Sources