HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICLowContained
THE HERTZ CORPORATION
bd_187c098532029f32 · schema v1 · pii pii-v1
Full breach record for THE HERTZ CORPORATION →The Hertz Corporation issued a supplemental breach notification to Delaware regarding a cybersecurity incident involving third-party vendor Cleo Communications US, LLC. On February 10, 2025, Hertz confirmed that an unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in late 2024 to acquire Hertz data. The incident involved customer contact information. Hertz reported the event to law enforcement, engaged Kroll for two years of identity monitoring, and is notifying relevant regulators.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_4d9936b8024bb49aDelaware State AGfiled 2024-06-24Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2025/04/Hertz.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 24, 2024
- Raw hash
- 6bb4b52a340cae1d0f8493678d043330482970e4361d30b96cb6c98ffc7ddc7e
Reporting entity
- Name
- THE HERTZ CORPORATIONnorm: the hertz
Victim entity
- Name
- THE HERTZ CORPORATIONnorm: the hertz
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reporting the event to relevant regulators
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.