Monday, April 28, 2025
HomeCVE/vulnerabilityHertz Data Breach Exposes Customer Personal Information to Hackers

Hertz Data Breach Exposes Customer Personal Information to Hackers

Published on

SIEM as a Service

Follow Us on Google News

The Hertz Corporation has confirmed that sensitive personal information belonging to customers of its Hertz, Dollar, and Thrifty brands was compromised after hackers targeted a vendor’s file transfer platform.

The breach has sparked concerns about identity theft and privacy, prompting Hertz to offer free identity monitoring services for affected individuals.

According to an official notice issued by Hertz, the breach stemmed from an attack on Cleo Communications US, LLC (“Cleo”), a third-party vendor that manages a file transfer platform for the car rental giant.

- Advertisement - Google News

The platform was exploited through zero-day vulnerabilities in October and December 2024, allowing unauthorized parties to acquire Hertz data.

Hertz stated it became aware of the breach on February 10, 2025, and completed a comprehensive analysis by April 2, 2025, to determine the scope of affected data and individuals.

Scope of the Breach

The potentially exposed information includes:

  • Names
  • Contact details
  • Dates of birth
  • Credit card information
  • Drivers’ license data
  • Information related to workers’ compensation claims

For a small subset of individuals, additional sensitive information—such as Social Security numbers, passport information, Medicare or Medicaid IDs, and injury data related to vehicle accident claims—may also have been exposed.

Hertz emphasized that, to date, there is no evidence of fraudulent use of the compromised data.

Still, the corporation is urging those affected to remain vigilant, monitor their financial accounts, and check their credit reports for unusual activity.

Company Response and Customer Support

Hertz has confirmed that Cleo has taken steps to investigate and secure the vulnerabilities that led to the incident.

The incident has been reported to law enforcement and relevant regulators, demonstrating Hertz’s commitment to transparency and regulatory compliance.

To assist potentially impacted individuals, Hertz has contracted Kroll, a prominent risk consultancy, to provide two years of complimentary identity or dark web monitoring services.

U.S. residents who may have been affected are encouraged to sign up for these services at Kroll’s registration page.

Advice for Customers

While no misuse of information has been reported, experts recommend that customers:

  • Regularly review bank and credit card statements
  • Obtain free annual credit reports from major credit bureaus
  • Consider placing a fraud alert or credit freeze on their credit files

Customers with questions can contact Hertz’s dedicated helpline at (866) 408-8964, Monday through Friday from 6:00 a.m. to 8:00 p.m. Central Time.

The breach highlights ongoing challenges in securing personal data across digital platforms and serves as a stark reminder of the importance of cybersecurity vigilance for businesses and consumers alike.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Critical FastCGI Library Flaw Exposes Embedded Devices to Code Execution

A severe vulnerability (CVE-2025-23016) in the FastCGI library-a core component of lightweight web server...

Viasat Modems Zero-Day Vulnerabilities Let Attackers Execute Remote Code

A severe zero-day vulnerability has been uncovered in multiple Viasat satellite modem models, including...

Obfuscation Techniques: A Key Weapon in the Ongoing War Between Hackers and Defenders

Obfuscation stands as a powerful weapon for attackers seeking to shield their malicious code...

React Router Vulnerabilities Allow Attackers to Spoof Content and Alter Values

The widely used React Router library, a critical navigation tool for React applications, has...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Critical FastCGI Library Flaw Exposes Embedded Devices to Code Execution

A severe vulnerability (CVE-2025-23016) in the FastCGI library-a core component of lightweight web server...

Viasat Modems Zero-Day Vulnerabilities Let Attackers Execute Remote Code

A severe zero-day vulnerability has been uncovered in multiple Viasat satellite modem models, including...

Obfuscation Techniques: A Key Weapon in the Ongoing War Between Hackers and Defenders

Obfuscation stands as a powerful weapon for attackers seeking to shield their malicious code...