DisclosureLens
HackingRetail & ConsumerTransportation & LogisticsRetailVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedMulti-Stage ChainGovernment IDFinancial accountHealth (basic)Identity (basic)CriticalContained

THE HERTZ CORPORATION

bd_4d9936b8024bb49a · schema v1 · pii pii-v1

Severity

Critical

Discovered

Oct 1, 2024

Filed

Jun 24, 2024

To disclose

Affected · nationwide

1,613,7736,647 in this filing

Confidence

65%
Full breach record for THE HERTZ CORPORATION3 incidents on file

Hertz Corporation notified Delaware AG of a supply-chain breach involving vendor Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in Oct/Dec 2024 to exfiltrate data. Hertz confirmed the scope on April 2, 2025. Over 1.6 million individuals affected, including 6,647 Delaware residents. Data included SSNs, driver's licenses, financial account numbers, and medical history. Hertz engaged Kroll for identity monitoring and reported to law enforcement.

Incident timeline — partial

? — ?

Breach window unknown

Jun 24, 2024

Filed

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1,613,773 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.