Potentially huge Hertz data breach sees customer personal info and driver licenses stolen

 Potentially huge Hertz data breach sees customer personal info and driver licenses stolen

Published on April 15, 2025 | Category: tech

Potentially huge Hertz data breach sees customer personal info and driver licenses stolen

News
By Sead Fadilpašić published

Hertz confirms data breach, but not the number of affected people

Hacking warning on a computer screen.
(Image credit: Shutterstock / Sashkin)

  • Car rental giant Hertz confirms suffering a data breach
  • The attack occurred through Cleo, a file transfer service provider
  • The threat actors abused a zero-day to get in

Car rental giant Hertz has confirmed suffering cyberattack which saw it lose sensitive customer information.

In a data breach notification letter published on its website, the company said that the incident involved Cleo Communications, a software company that provided file transfer services for Hertz “for limited purposes”.

The report says an unidentified threat actor exploited a zero-day vulnerability in the Cleo platform to exfiltrate sensitive data in October and December 2024. The attack was spotted in mid-February 2025, prompting an investigation, with the analysis concluding some customer data was taken.

Monitor your credit score with TransUnion starting at $29.95/month

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)

View Deal

Hallucinating malware

“We completed this data analysis on April 2, 2025, and concluded that the personal information involved in this event may include the following: name, contact information, date of birth, credit card information, driver’s license information and information related to workers’ compensation claims,” the announcement reads.

“A very small number of individuals may have had their Social Security or other government identification numbers, passport information, Medicare or Medicaid ID (associated with workers’ compensation claims), or injury-related information associated with vehicle accident claims impacted by the event.”

The exact number of affected individuals is not known at this time, with a company spokesperson saying it would be, “inaccurate to say millions” of customers are affected.

The identity of the attackers, or the nature of the breach, is also unknown at this time. It most likely wasn’t a ransomware attack, since it took the company months to realize it was hacked. That being said, this was most likely a simple data smash-and-grab.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

To mitigate the damages, Hertz is offering two years of identity monitoring and dark web monitoring services to potentially impacted individuals, through Kroll, at no cost.

At press time, there was no evidence that the stolen data was misused in any way.

Via TechCrunch

You might also like

  • Cl0p resurgence drives ransomware attacks to new highs in 2025
  • Take a look at our guide to the best authenticator app
  • We've rounded up the best password managers
Sead Fadilpašić

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Related Articles

Spotify is about to be flooded with AI-made ads, and I wonder if it will make much of a difference to businesses

Spotify’s new AI-powered ad tool may not be the solution they claim....

Read More
CinemaCon 2025 live – first Avatar 3 reaction, juicy Fantastic Four news,

CinemaCon 2025 is officially underway – here are all new movie announc...

Read More
NYT Wordle today — answer and my hints for game #1385, Friday, April 4

Looking for Wordle hints? I can help. Plus get the answers to Wordle t...

Read More