Data Breaches

Hertz Data Breach: Driver’s Licenses and Financial Details at Risk

0

Hertz Corporation has confirmed a data breach that compromised personal information of customers associated with its Hertz, Thrifty, and Dollar brands. The breach stemmed from zero-day vulnerabilities exploited in Cleo’s managed file transfer platforms during attacks in late 2024.

In a notice issued on February 10, 2025, the car rental company stated that Hertz data was acquired by an unauthorized third party that exploited zero-day vulnerabilities in Cleo’s platform during incidents in October and December 2024.

Hertz promptly launched an investigation to determine the scope of the breach and identify affected individuals.

According to the company, the exposed data may include names, contact details, dates of birth, credit card numbers, driver’s license information, and workers’ compensation claim details. A smaller subset of individuals may have had even more sensitive data compromised, such as Social Security numbers, government-issued IDs, passport information, and medical ID numbers tied to accident-related claims.

Although Hertz has not disclosed the total number of impacted customers, notifications were sent out in Maine, where 3,409 individuals were confirmed affected. Notifications were also issued in California and Vermont, though without reported figures.

To assist impacted customers, Hertz is offering two years of free identity monitoring services. The company confirmed that, so far, there is no evidence of the stolen data being misused for fraud.

However, the Clop ransomware group, known for exploiting zero-day vulnerabilities in file transfer tools, has claimed responsibility for the attack and reportedly leaked Hertz’s data on its extortion site. The group had earlier admitted to stealing data from 66 companies during a widespread exploitation campaign targeting Cleo platforms like Harmony, VLTrader, and LexiCom.

Since 2020, Clop has shifted its focus from traditional ransomware to data theft and extortion, leveraging unpatched vulnerabilities in secure file transfer software. The group has also been linked to high-profile breaches involving platforms such as MOVEit Transfer, GoAnywhere MFT, SolarWinds Serv-U, and Accellion FTA.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Critical WhatsApp bug lets hackers exploit file attachments on Windows

Previous article

TikTok fined €530 M over unlawful data transfers to China

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *