Yes, U-Haul customer driver’s license information was exposed during two separate data breaches at the rental company. In September 2022 and again in December 2023, attackers gained unauthorized access to U-Haul’s rental contracts search portal after compromising employee login credentials, exposing the names and driver’s license numbers of approximately 2.2 million customers. This exposure created significant privacy risks, as driver’s licenses contain sensitive personal identification that criminals commonly use for identity theft.
U-Haul has agreed to pay $5,085,000 to settle the class action lawsuit related to these breaches, with affected customers eligible to submit claims for compensation. The settlement does not constitute an admission of wrongdoing by U-Haul, but it reflects the company’s decision to resolve litigation rather than continue defending against claims of inadequate data security. Customers who rented from U-Haul during the affected periods and had their information compromised have the opportunity to receive compensation through this settlement.
Table of Contents
- What Personal Information Was Compromised in the U-Haul Data Breach?
- How Did Hackers Access U-Haul’s Rental Contracts Database?
- The U-Haul Settlement: Payment Amounts and Eligibility
- How to Protect Yourself After the U-Haul Data Breach
- Why Driver’s License Information in the Hands of Criminals Is Particularly Dangerous
- Comparing the U-Haul Breach to Other Major Data Breaches Involving Identification Information
- U-Haul’s Response and What the Settlement Reveals About Corporate Data Security Practices
- Conclusion
What Personal Information Was Compromised in the U-Haul Data Breach?
The unauthorized access to U-Haul’s rental contracts portal specifically exposed customers’ names and driver’s license numbers—two pieces of information that, when combined, present a substantial identity theft risk. Driver’s licenses contain multiple data points that thieves value, including address information, issue dates, and identification numbers that can be used to open fraudulent accounts or apply for credit in a victim’s name. Unlike passwords that can be changed, a compromised driver’s license number remains a vulnerability that persists indefinitely.
The breach occurred across two distinct timeframes: once in September 2022 and again in December 2023. This means that some customers experienced exposure during a single incident, while others whose rental contracts remained searchable in the system could have been compromised during both periods. The extended timeline of the second breach, discovered months after the initial incident, suggests that U-Haul’s security measures may not have been sufficient to detect and quickly stop the unauthorized access.

How Did Hackers Access U-Haul’s Rental Contracts Database?
The attackers gained access to U-Haul’s rental contracts search portal by compromising two unique employee passwords, giving them entry into a system designed to store sensitive customer rental information. This breach method highlights a common corporate security vulnerability: even systems with legitimate access controls remain at risk when employee credentials are compromised through phishing, leaked password databases, or other credential theft methods. Once inside the system, the attackers could search through and extract customer data without triggering alerts.
What makes this particular vulnerability concerning is that the rental contracts portal should theoretically be one of U-Haul’s more secure systems, given the sensitive nature of customer information it contains. The fact that compromising just two passwords allowed such widespread data access suggests that U-Haul may have lacked additional security layers such as multi-factor authentication, rate limiting on searches, or monitoring systems that would flag suspicious database queries. The December 2023 breach occurred months after the September incident, indicating that U-Haul’s remediation efforts may not have fully addressed the underlying security gaps.
The U-Haul Settlement: Payment Amounts and Eligibility
The $5,085,000 settlement fund is non-reversionary, meaning that all money designated for customer payments will be distributed rather than reverting to U-Haul if fewer claims are filed than expected. Each eligible customer receives a base amount of $100, with the potential for payments to reach $200 or more per claimant if the total number of valid claims is lower than anticipated. This variable payment structure is common in class action settlements, as it allows the fund to be distributed proportionally based on actual claim volume.
To qualify for compensation, customers generally must have had a rental contract or interaction with U-Haul during the periods when the breaches occurred, making them part of the affected 2.2 million customer group. The settlement applies to anyone whose personal information was exposed in either the September 2022 or December 2023 incident. However, the original claims deadline of October 15, 2024, has already passed for this particular settlement, which means prospective claimants will need to verify current deadlines through official settlement administration channels before submitting a claim.

How to Protect Yourself After the U-Haul Data Breach
As part of the settlement, U-Haul is offering affected customers one year of complimentary identity theft protection services through Equifax, which provides credit monitoring and fraud detection capabilities. This service is valuable but limited in scope—one year of protection covers the immediate risk period but does not address long-term exposure. Customers should consider enrolling in this service immediately upon notification, as it typically requires activation within a specified timeframe to be effective.
Beyond the settlement-provided protection, affected individuals should take independent steps to safeguard their identity. Placing a security freeze on your credit reports with all three major credit bureaus (Equifax, Experian, and TransUnion) prevents criminals from opening accounts in your name, even if they have your driver’s license number. You should also monitor credit card and bank statements regularly for unauthorized charges and consider subscribing to a credit monitoring service beyond the one-year period offered through the settlement. Additionally, be cautious of phishing emails claiming to be from U-Haul or settlement administrators, as scammers often exploit breaches to steal additional information from victims.
Why Driver’s License Information in the Hands of Criminals Is Particularly Dangerous
Driver’s license numbers are prized by identity thieves because they serve as a gateway credential for committing deeper fraud. With your name and driver’s license number, a criminal can apply for loans, open utility accounts, file fraudulent tax returns, or apply for government benefits in your name. Unlike compromised credit card numbers, which can be disputed and replaced, driver’s license fraud can take months or years to fully resolve, as you must navigate both law enforcement and administrative channels to reclaim your identity.
The risk is particularly acute for individuals who do not actively monitor their financial accounts or credit reports. Someone whose information was exposed could have fraudulent accounts opened in their name months or even years after the breach, and they might not discover the crime until collection agencies contact them or their credit score suddenly drops. This delayed discovery period means that preventive measures like credit freezes and ongoing monitoring are critical—waiting to respond only after you discover fraud has occurred leaves you vulnerable to compound losses. Furthermore, if a thief uses your driver’s license information to commit crimes themselves, you may face complications with law enforcement or background checks.

Comparing the U-Haul Breach to Other Major Data Breaches Involving Identification Information
The U-Haul breach is consistent with a troubling trend of companies failing to adequately protect customer identification documents. Similar breaches involving driver’s license or passport information have exposed millions of people at companies ranging from healthcare providers to financial institutions. The primary difference in the U-Haul case is the mechanism of access—attackers obtained credentials rather than exploiting a vulnerable website or unencrypted database—but the outcome for customers is identical: permanent exposure of identification information that cannot be replaced or revoked.
What distinguishes the U-Haul settlement from some comparable breaches is the inclusion of free identity theft protection services as part of the remedy. In some past class actions involving identification document theft, companies have offered only credit monitoring, which is reactive rather than preventive. The addition of fraud detection services in the U-Haul settlement reflects a recognition that the exposed data creates specific and elevated risks requiring more comprehensive protective measures than standard credit monitoring alone.
U-Haul’s Response and What the Settlement Reveals About Corporate Data Security Practices
U-Haul has consistently maintained that it did not admit to any wrongdoing in agreeing to the settlement, characterizing the decision as a practical choice to avoid the costs and uncertainties of continued litigation. From a legal standpoint, this is a standard position that companies take in most class action settlements—resolving a case does not constitute a legal admission of negligence. However, the company’s agreement to pay $5,085,000 and provide identity theft protection services indicates that U-Haul recognized the potential liability and reputational damage of allowing the case to proceed to trial.
The settlement also reflects a broader reality about corporate data security in the modern era: even major companies with substantial resources sometimes have inadequate security practices. The fact that two employee passwords were sufficient to breach U-Haul’s system suggests that the company had not implemented baseline security measures like multi-factor authentication on systems containing sensitive customer information. While attackers will always be resourceful, the existence of exploitable security gaps indicates that the company had not prioritized data protection at a level consistent with the sensitivity of the information being stored.
Conclusion
The U-Haul data breach exposed millions of customers’ driver’s license information through two separate unauthorized access incidents in 2022 and 2023. The $5,085,000 settlement provides compensation of at least $100 per claimant, along with one year of complimentary identity theft protection services through Equifax. Given the severity of identity risks created by driver’s license theft, affected customers should take proactive steps to protect themselves, including placing credit freezes and monitoring accounts closely for fraudulent activity.
If you were a U-Haul customer during the breach periods and have not yet submitted a claim, check the current status of the settlement administration website to determine if the claims deadline has been extended or if you remain eligible to file. Even after the official settlement period closes, you should maintain heightened vigilance against identity theft, as criminals often exploit stolen driver’s license information months or years after a breach occurs. Consider maintaining ongoing credit monitoring and security measures well beyond the one-year period covered by U-Haul’s settlement offer.
You Might Also Like
- Oracle Data Breach Litigation Claims Customer Information Was Exposed
- Union Home Mortgage Data Breach Litigation Claims Borrower Information Was Exposed
- City of Hope Data Breach Settlement Claims Patient Information Was Compromised
Open Settlements You Can Claim Now
Browse current class action settlements accepting claims — several require no proof of purchase:
