The Yellow Corporation 2025 data breach was an unauthorized file-access and data-exfiltration event on March 27, 2025, in the computer network of the former freight carrier while it was in bankruptcy proceedings. Yellow detected suspicious activity that day, briefly took systems offline, securely restored them from backups, and began an extensive investigation with third-party cybersecurity specialists.
According to the company's official notice, the substantial majority of affected information relates to former Yellow employees. Files may have contained identity, government-document, financial-account, payment-card, medical, and health-insurance information. State subsets were published for Texas, Massachusetts, and Vermont, but no deduplicated nationwide total was disclosed. LeakData keeps pwnCount and totalRecords at zero; importedRecordCount is zero.
How Was the Yellow Corporation Breach Confirmed?
The primary source is Yellow Corporation's “Notice of Data Security Event,” dated June 26, 2026, on its own domain. The company PDF directly states the incident date, unauthorized access and exfiltration finding, file review, confirmed data classes, concentration among former employees, and security measures taken.
A Massachusetts consumer-notification file supports the same official text and regulatory disclosure route. Claim Depot links the company page and state records including Massachusetts, California, Vermont, and South Carolina and summarizes the timeline and available person subsets. The sources align on the existence of the event, date, data acquisition, and core information types.
What Happened on March 27, 2025?
Yellow identified suspicious activity on its computer network around March 27. The organization promptly began an investigation, engaged third-party cybersecurity specialists, briefly took systems offline, and restored them from secure backups. The review found that certain network files were accessed without permission and exfiltrated that same day.
After identifying the affected files, the company conducted a comprehensive review to determine their contents and the people to whom the information related. The public notice does not name the actor, initial entry method, malware, ransom demand, or whether the data was publicly released. LeakData records the confirmed exfiltration without adding undisclosed technical details.
What Identity and Government-Document Information Was Affected?
Possible fields include names, Social security numbers, dates of birth, driver's-license or state-identification-card numbers, passport numbers, and other government-issued identification-card numbers. Because information varied by person, every field should not be assumed to have existed in every file or for every former employee.
A combination of SSN, birth date, and government ID creates substantial risk of fraudulent credit applications, tax-identity misuse, unemployment-benefit fraud, and convincing targeted phishing. Former employees should be especially cautious of messages impersonating the company's bankruptcy or human-resources processes. Documents or verification codes should not be provided through unexpected Yellow-branded links.
What Financial and Payment Information Was In Scope?
The official notice separately lists financial-account numbers and payment-card numbers. Those fields may enable unauthorized payments, abuse of account-verification processes, or scams impersonating a bank. Because the company emphasizes the historical nature of the data, closed-account identifiers and fields that may remain active could exist within the same file population.
The public text does not specifically confirm a bank name, account type, routing number, card expiration date, CVV, PIN, online-banking password, or transaction history. LeakData does not add those subfields or present a payment-card number as a complete financial profile. Recipients should review both older and current accounts for unfamiliar transactions or new creditors.
Why Was Medical and Health-Insurance Information Present?
Yellow confirmed that the affected files may have contained medical information and health-insurance information. Because most records belonged to former employees, those categories could relate to employee benefits, leave, workplace injuries, or insurance administration, but the official notice does not confirm a particular source.
The document does not publish clinical subfields such as diagnoses, treatments, prescriptions, medical-record numbers, insurance-policy numbers, service dates, or provider names. LeakData records only the confirmed broad health classes. Former employees should review health-insurance explanation-of-benefits statements and provider bills for unfamiliar services or claims.
How Many People Were Affected and How Did Yellow Respond?
Source-linked state records report 13,183 Texas, 491 Massachusetts, and 37 Vermont residents. These are distinct state subsets, not a deduplicated total for the United States. LeakData does not add them together and label the result as the national count; pwnCount and totalRecords remain zero. No employee or other individual rows were imported, so importedRecordCount is zero.
Yellow secured systems, conducted a comprehensive investigation, implemented additional technical safeguards, and published a public notice. A help line at 833-289-4340 was established from 9:00 a.m. to 9:00 p.m. Eastern on weekdays. Recipients should monitor credit reports, bank and card statements, and health-insurance activity; when an SSN was involved, a credit freeze, fraud alert, and IRS Identity Protection PIN may be appropriate.