Avis breach of a business application exposed data on 299,006 customers
- Organization
- Avis Rent A Car System
- Exploit
- Hacking
- Industry
- Travel & Tourism
Avis Rent A Car System told regulators in September 2024 that an intruder had reached one of its business applications and taken customer data. A filing with the Office of the Maine Attorney General put the number of affected individuals at 299,006, and The Register reported that some customers in the United Kingdom were included.
The company said the unauthorised access took place between 3 and 6 August 2024. Accounts of when it was found differ: Infosecurity Magazine reported discovery on 5 August, while The Register cited 14 August. The exposed fields included names, mailing addresses, email addresses, phone numbers, dates of birth, driver's licence numbers, and credit card numbers with expiry dates.
The cause was described inconsistently as well. The Maine filing categorised the incident as insider wrongdoing, while the notification letter sent to customers referred to an unauthorised third party gaining access to a business application and made no mention of an employee. Avis did not publicly reconcile the two descriptions.
Avis said it blocked access to the affected application on discovery, investigated with outside cybersecurity specialists, notified law enforcement and filed breach notices with state attorneys general. It offered affected customers a year of credit monitoring through Equifax, with an enrolment deadline of 31 December, and said it had deployed additional safeguards and reviewed its security controls. Avis Rent A Car System is part of Avis Budget Group, which also operates the Budget and Zipcar brands.