UHaul Data Breach

  • >some rental contracts were accessed between November 5, 2021, and April 5, 2022

    >None of our financial, payment processing or U-Haul email systems were involved; the access was limited to the customer contract search tool.

    So they were in U-Haul's network for 5 months, but U-Haul is dead sure they only got into a single system.

    I hate it when they phrase things in this overly confident way. I do believe they didn't see overt evidence that other systems were compromised, but that doesn't mean it didn't happen.

  • Last time I rented a U-Haul, they asked to see my driver's license as expected - then took a picture of the front and back to store in their systems.

    I did not like the taking a picture of the entire license at all, but was stuck.

    I had full expectation that a non-tech company like U-Hual would be fully incompetent to properly store such a trove of identity information, and here it is - crackers wandering around in their system for six months, and they "have no evidence" of further intrusion, meaning they don't even have the logs to verify or the capability to read the logs, so they actually have no evidence that other data was not accessed (absence of evidence is not evidence of absence)...

    I'll sure as hell be avoiding UHaul if at all possible in the future...

  • Same thing happened to me. I care MUCH less about my credit card being leaked then the picture & details of my Drivers License being out there. Last time I give them any money.

  • If it were me, which it wasn't, I'd be looking for the rentals being made by a certain white supremacist group that likes to use U-Hauls to transport their masked goons around the country.

  • Uhaul is such a dumpster of a Dino company it Wouldn’t surprise me if they secured everything with “password”. I hate them with a passion