Data breach
Hertz
- Records
- 5,333,838
- Breach date
- 10 April 2025Estimated
- Added
- 30 April 2025
What was exposed
10 types of data · 4 more reported · 2 put you at serious risk
- Email addresses5,333,838
- Names1,493,761
- Home addresses1,493,761
- Vehicle VINs1,374,421
- Licence plates1,003,881
- Street addresses295,273
- Phone numbers106,905
- Dates of birth29,693
- Passport numbers6
- Social security numbers1
- Card numbersReported, not counted
- Driving licence numbersReported, not counted
- Government IDsReported, not counted
- Medical recordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Hertz has confirmed that personal data belonging to millions of the company's customers and rental records was stolen in a cyberattack that targeted one of its vendors rather than the rental company itself. According to our investigation team, the listing contains 5,333,838 rows of data tied to the incident, and the listing was added to our records on April 30, 2025, with an estimated attack date of April 10, 2025. The breach stemmed from zero-day vulnerabilities in the file transfer platform operated by Cleo Communications US LLC, a vendor Hertz used for limited file transfer purposes. Reporting by Malwarebytes linked the campaign to the CL0P ransomware group, which exploited the same Cleo flaws to hit many companies at once. Hertz, in a notice filed with state attorneys general, said it found no forensic evidence that its own network was affected.
October and December 2024: An unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform, including flaws tracked as CVE-2024-50623 and CVE-2024-55956, and acquired Hertz data during this window, according to Hertz's notice filed with the Iowa Attorney General.
February 10, 2025: Hertz confirmed that its data had been acquired by the unauthorized third party, per the same notice.
April 2, 2025: Hertz completed its analysis of the stolen data, according to the notice and reporting by Cybersecurity Dive.
April 11, 2025: Hertz began mailing notification letters to potentially affected individuals and posted a notice on its websites, per the Iowa filing. Bloomberg also reported the customer alert that week.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (5,333,838), names (1,493,761), home addresses (1,493,761), vehicle identification numbers (1,374,421), vehicle plates (1,003,881), street addresses (295,273), phone numbers (106,905), dates of birth (29,693), and passport numbers (6). The number of Social Security numbers present could not be determined from the indexed data.
Hertz's notification letter, filed with the Iowa Attorney General, listed additional details. It said the affected information may include names, contact information, dates of birth, payment card information, driver's license information, and information related to workers' compensation claims. A very small number of individuals may have had Social Security numbers or other government identification numbers, passport information, Medicare or Medicaid ID associated with workers' compensation claims, or injury-related information connected to vehicle accident claims exposed.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The exposure of driver's license numbers, dates of birth, and home addresses gives fraudsters material for identity theft, targeted phishing, and convincing scams that reference real rental activity. Payment card information was also involved, so affected people should watch statements for unauthorized charges. For the small group whose Social Security numbers or workers' compensation and injury-related details were exposed, the risk of account takeover and fraudulent claims is higher. Stolen vehicle data, such as VINs and plates, could also support fraudulent vehicle-related schemes. Hertz said it was not aware of any misuse of the information for fraudulent purposes as of its notice.
What Is Hertz Doing in Response?
Hertz reported the event to law enforcement and began notifying regulators. Starting April 11, 2025, the company mailed notification letters and notified people by email and through notices on its websites. Hertz arranged two years of free identity monitoring services through Kroll for potentially affected individuals, who could enroll through a link in the notice. The company also said Cleo took steps to investigate the event and fix the identified vulnerabilities.
What Should You Do If You Were Affected?
If you received a notification letter from Hertz, enroll in the free Kroll identity monitoring services offered, as the letters include an activation deadline. Check credit card and bank statements for charges you do not recognize, and review your credit reports for accounts you did not open. Consider placing a fraud alert or a credit freeze with Equifax, Experian, and TransUnion. Be cautious of phishing emails or calls that reference your rental history, license number, or an accident claim, and never share personal details in response to unexpected contacts.
In the news
- Malwarebytes: Hertz data breach caused by CL0P ransomware attack on vendormalwarebytes.com (opens in a new tab)
- Cybersecurity Dive: Hertz says personal data breached in connection with Cleo file-transfer flawscybersecuritydive.com (opens in a new tab)
- Bloomberg: Hertz Says Hackers Stole License Numbers, Credit Card Databloomberg.com (opens in a new tab)
- Iowa Attorney General: Hertz Corporation notice of privacy event (April 11, 2025)iowaattorneygeneral.gov (opens in a new tab)
