HomeNewsBreachesAPIAboutAccount
hertz-2025

Hertz Breach

Apr 10, 2025

1,493,762 rows

Added on Apr 30, 2025
Data Found in the Breach
Email
Name
Home Address

Search the Leak

Email
OR
Full Name

What happened in the Hertz Breach?

DataBreach.com Team · April 29th 2025, 8:00 pm EDT

In 2025, Hertz publicly confirmed a data breach that stemmed from a cyberattack on one of its third-party vendors, Cleo, a company specializing in data integration and file transfer services. The breach was the result of a targeted campaign by the CL0P ransomware group, which exploited previously unknown vulnerabilities in Cleo’s software. Between October and December 2024, attackers gained unauthorized access to data belonging to Hertz, using Cleo’s platform as a gateway. The breach is one of several incidents linked to CL0P's widespread exploitation of file transfer systems during this period.

The exposed data includes customer information that had been transmitted through Cleo's platform, potentially as part of routine business operations such as reservation management, customer communication, or account updates. While Hertz has not released a detailed account of what information was accessed, the breach reportedly involves data that could affect the privacy of thousands of customers. The stolen records may contain identifying information linked to Hertz rental activity and customer profiles, prompting concerns about fraud and identity misuse.

According to The Record, The information stolen includes contact information, payment card information, driver’s licenses and information related to worker’s compensation claims. Others had Social Security numbers, government IDs, passports, Medicare or Medicaid ID, or injury-related information associated with vehicle accident claims leaked through the hack.

Hertz became aware of the intrusion after Cleo disclosed the vulnerability and its potential impact on client data. Subsequent internal investigations confirmed that unauthorized parties had accessed information during the three-month window. The car rental giant began notifying affected customers in early 2025, encouraging them to remain alert to possible misuse of their data and offering identity protection services to those at higher risk.

Created and maintained by
For media inquiries, contact us at contact@databreach.com