THE HERTZ CORPORATION
bd_2c96b0a6f7ae2ca6 · schema v1 · pii pii-v1
Full breach record for THE HERTZ CORPORATION →3 incidents on fileThe Hertz Corporation reported a third-party supply chain breach involving vendor Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in October and December 2024. Hertz discovered the incident on February 10, 2025, and notified affected individuals on April 11, 2025. The breach impacted customer contact information. 3,409 Maine residents were affected. Hertz engaged Kroll to provide two years of identity monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 1, 2024
Begins
Feb 10, 2025
Discovered
Apr 11, 2025
Filed
vs. sector median
+1 wks slower
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- Washington State AGbd_3f5803c2f674c4ba2025-04-11Verified
- Montana State AGbd_88c1a4f18148e5ca2025-04-11Verified
- California State AGbd_a4ca81d4d55c4b9b2025-04-11Verified
- Delaware State AGbd_bae3ed4100ea194a2025-04-11Verified
Show 5 more filings ↓Show fewer ↑up to 10d gap
- Nebraska State AGbd_d6a8b36608cf60032025-04-11Verified
- Vermont State AGbd_f5e59707561fd35b2025-04-11Verified
- Rhode Island State AGbd_82f3b7bd9ca1832e2025-04-14 · +3dVerified
- New Hampshire State AGbd_ac4d00b21e3d316a2025-04-14 · +3dVerified
- Illinois State AGbd_b3aa3f6351a7be422025-04-01 · +10dVerified
Filing propagation · 10 filings · 10 states
View merged incident ↗Pattern: first filing Apr 1 (IL), last Apr 14 (NH) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.