Hertz Suffers Data Breach: Customer Information Compromised, Potentially Involving Licenses and Social Security Numbers
This week, car rental company Hertz informed its users about a significant data breach that has exposed some customers’ personal information. On Monday, April 14, TechCrunch reported the appearance of a Notice of Data Incident on the Hertz website. According to the notice, personal information including names, contact details, date of birth, credit card information, driver’s license details, and “information related to workers’ compensation claims” may have been compromised through an external vendor known as Cleo. Additionally, Social Security numbers, government IDs, passport information, Medicare or Medicaid IDs, and medical details from car accident claims could also have been stolen from “a very small number of individuals,” as stated in the notice. Hertz detected the breach on February 10, with customer data being compromised in October and December of the previous year.
The notice did not specify how many customers’ personal information was affected. However, a copy of the notice issued to residents in Maine (published by the Office of the Maine Attorney General) indicated that 3,409 customers in Maine alone were impacted. This suggests that the total number of affected individuals is likely much larger, especially since notifications were also sent to customers in Australia, Canada, New Zealand, the United Kingdom, and other regions. A spokesperson for Hertz refrained from providing specific figures but noted that “it would be inaccurate to say millions of customers are affected.”
The breach originated with a Hertz vendor, Cleo, which manages file-sharing platforms for the company. “On February 10, 2025, we confirmed that Hertz data was acquired by an unauthorized third party that we understand exploited zero-day vulnerabilities within Cleo’s platform in October and December 2024,” the notice stated. Hertz did not reveal additional details about the hack or those responsible, but during that period, cybersecurity firm Huntress reported “evidence of threat actors exploiting this [Cleo software].” Around the same time, the ransomware group Clop claimed responsibility for data theft attacks targeting Cleo’s servers. While the notice indicated that Hertz was “not aware of any misuse of personal information for fraudulent purposes in connection with the event,” it advised customers to “remain vigilant” regarding data breaches and provided resources on how to monitor account statements and credit reports, including instructions for placing a fraud alert or credit freeze on their accounts. Certain Hertz customers will also receive “two years of identity monitoring services” at no cost.
UPDATE: Apr. 15, 2025, 5:30 p.m. EDT. This story has been updated with new information from a Hertz representative.
Topics
Cybersecurity
Privacy
