THE HERTZ CORPORATION
bd_3f5803c2f674c4ba · schema v1 · pii pii-v1
Full breach record for THE HERTZ CORPORATION →3 incidents on fileThe Hertz Corporation notified Washington AG of a breach involving vendor Cleo Communications US LLC. An unauthorized third party exploited zero-day vulnerabilities (CVE-2024-50623, CVE-2024-55956) in Cleo's file transfer platform in Oct/Dec 2024. Hertz confirmed data acquisition on Feb 10, 2025. ~19,297 Washington residents affected. Data included names, DOB, payment card info, driver's licenses, and SSNs. Notifications began April 11, 2025, including 2 years of Kroll identity monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 1, 2024
Begins
Feb 10, 2025
Discovered
Apr 11, 2025
Filed
vs. sector median
+1 wks slower
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- Maine State AGbd_2c96b0a6f7ae2ca62025-04-11Candidate
- Montana State AGbd_88c1a4f18148e5ca2025-04-11Verified
- California State AGbd_a4ca81d4d55c4b9b2025-04-11Verified
- Delaware State AGbd_bae3ed4100ea194a2025-04-11Verified
Show 5 more filings ↓Show fewer ↑up to 10d gap
- Nebraska State AGbd_d6a8b36608cf60032025-04-11Verified
- Vermont State AGbd_f5e59707561fd35b2025-04-11Verified
- Rhode Island State AGbd_82f3b7bd9ca1832e2025-04-14 · +3dVerified
- New Hampshire State AGbd_ac4d00b21e3d316a2025-04-14 · +3dVerified
- Illinois State AGbd_b3aa3f6351a7be422025-04-01 · +10dVerified
Filing propagation · 10 filings · 10 states
View merged incident ↗Pattern: first filing Apr 1 (IL), last Apr 14 (NH) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.