Hertz confirmed customer data theft through the Cleo file transfer exploit
- Organization
- The Hertz Corporation
- Exploit
- Third-Party Data Breach
- Industry
- Travel & Leisure
The Hertz Corporation began notifying customers in April 2025 that their personal information had been stolen through zero day vulnerabilities in Cleo Communications' managed file transfer software, the same flaws behind a wider extortion campaign attributed to the Clop ransomware group.
Hertz said the data was taken from Cleo's platform in October and December 2024 and that it used the product for limited purposes. The company identified that data had been acquired on 10 February 2025, completed its analysis of the affected records on 2 April and started notifications on 11 April through email, mailed letters and a notice on its website. Hertz said its own network was not compromised.
The incident covered people associated with the Hertz, Dollar and Thrifty rental brands. Reported data types included names, contact details, dates of birth, payment card numbers, driver's licence numbers and information tied to workers' compensation claims. A smaller group also had Social Security or other government identification numbers, passport details, Medicare or Medicaid identifiers, or vehicle accident claim records involved.
Hertz did not publish a global total. State breach filings reviewed by The Record put the figure above 100,000 people, including 96,665 in Texas and 3,409 in Maine, with notifications also going to customers in California and Vermont. The company reported the matter to law enforcement and offered two years of identity and dark web monitoring through Kroll. Cleo had by then patched the exploited vulnerabilities.