2025 Yellow Corporation — network exfil during bankruptcy; ≥13,183 TX residents notified (2026)
Data compromised
Names, SSNs, dates of birth, driver’s license/state ID, passport and other government IDs, financial/payment card numbers, medical and health insurance information (per company notice); substantial majority former employees
Technical writeup
Verified company/regulator notices — June–July 2026. Yellow Corp. (debtor-in-possession, Delaware Ch. 11 Case No. 23-11069) identified suspicious network activity on or about March 27, 2025; investigation found files accessed and exfiltrated that day. June 26, 2026 website notice and state AG filings followed. Texas AG-facing reporting cites 13,183 Texas residents; additional filings include Massachusetts (491) and Vermont (37). National total not fully published in sources reviewed; catalog indexes 13183 as the largest attested state count. Most affected people were former employees. Workers later sued over delayed warning / protection failures during bankruptcy. Distinct from unrelated catalog company “Yellow” (yellow.com).
Root cause
Unauthorized access and exfiltration of files on Yellow’s computer network on or about March 27, 2025; discovered via suspicious activity; company notified in June 2026 while in Chapter 11
References
- https://myyellow.com/wp-content/uploads/2026/06/Yellow-Corporation-Website-Notice.pdf
- https://www.classaction.org/data-breach-lawsuits/yellow-corporation-june-2026
- https://www.claimdepot.com/data-breach/yellow-corporation-2026
- https://news.bloomberglaw.com/business-and-practice/bankrupt-trucker-yellow-sued-over-delayed-data-breach-warning
- https://oag.my.site.com/datasecuritybreachreport/apex/DataSecurityReportsPage