TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

UHaul Data Breach

92 pointsby mithusingh32over 2 years ago
I just received this email a few days ago:<p>We are writing to inform you of an incident that involved some of your information. We are providing this notice to explain the incident and measures we have taken, and also to provide some steps you can take in response.<p>What Happened? We detected a compromise of two unique passwords that were used to access a customer contract search tool that allows access to rental contracts for U-Haul customers. The search tool cannot access payment card information; no credit card information was accessed or acquired. Upon identifying the compromised passwords, we promptly changed the passwords to prevent any further unauthorized access to the search tool and started an investigation. Cybersecurity experts were engaged to identify the contracts and data that were involved. The investigation determined an unauthorized person accessed the customer contract search tool and some customer contracts. None of our financial, payment processing or U-Haul email systems were involved; the access was limited to the customer contract search tool.<p>What Information Was Involved? On August 1, 2022, our investigation determined some rental contracts were accessed between November 5, 2021, and April 5, 2022. After an in-depth analysis, our investigation determined on September 7, 2022, the accessed information includes your name and driver&#x27;s license or state identification number<p>Well its a nice email to wake up to. The first time I ever rent a uHaul and my DL is leaked.

5 comments

tyingqover 2 years ago
&gt;some rental contracts were accessed between November 5, 2021, and April 5, 2022<p>&gt;None of our financial, payment processing or U-Haul email systems were involved; the access was limited to the customer contract search tool.<p>So they were in U-Haul&#x27;s network for 5 months, but U-Haul is dead sure they only got into a single system.<p>I hate it when they phrase things in this overly confident way. I do believe they didn&#x27;t see overt evidence that other systems were compromised, but that doesn&#x27;t mean it didn&#x27;t happen.
评论 #32866090 未加载
评论 #32866088 未加载
toss1over 2 years ago
Last time I rented a U-Haul, they asked to see my driver&#x27;s license as expected - then took a picture of the front and back to store in their systems.<p>I did not like the taking a picture of the entire license at all, but was stuck.<p>I had full expectation that a non-tech company like U-Hual would be fully incompetent to properly store such a trove of identity information, and here it is - crackers wandering around in their system for six months, and they &quot;have no evidence&quot; of further intrusion, meaning they don&#x27;t even have the logs to verify or the capability to read the logs, so they actually have no evidence that other data was not accessed (absence of evidence is not evidence of absence)...<p>I&#x27;ll sure as hell be avoiding UHaul if at all possible in the future...
评论 #32867369 未加载
评论 #32868179 未加载
评论 #32869393 未加载
评论 #32866954 未加载
评论 #32867272 未加载
UI_at_80x24over 2 years ago
Same thing happened to me. I care MUCH less about my credit card being leaked then the picture &amp; details of my Drivers License being out there. Last time I give them any money.
评论 #32866534 未加载
评论 #32866519 未加载
MonkeyMalarkyover 2 years ago
If it were me, which it wasn&#x27;t, I&#x27;d be looking for the rentals being made by a certain white supremacist group that likes to use U-Hauls to transport their masked goons around the country.
评论 #32870645 未加载
rdtwoover 2 years ago
Uhaul is such a dumpster of a Dino company it Wouldn’t surprise me if they secured everything with “password”. I hate them with a passion