HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
THE HERTZ CORPORATION
bd_4d9936b8024bb49a · schema v1 · pii pii-v1
Full breach record for THE HERTZ CORPORATION →The Hertz Corporation notified individuals of a data breach involving its third-party vendor, Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in October and December 2024 to acquire Hertz data. Hertz confirmed the incident on February 10, 2025, and engaged Kroll to provide two years of identity monitoring services. The breach potentially exposed customer names, contact information, and government identifiers.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_187c098532029f32Delaware State AGfiled 2024-06-24Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2025/04/Hertz.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 24, 2024
- Raw hash
- 438d5c7814f755ef72cf73641abe48e1086cd1bb566dfd5dde6e327689bdc4ac
Reporting entity
- Name
- THE HERTZ CORPORATIONnorm: the hertz
Victim entity
- Name
- THE HERTZ CORPORATIONnorm: the hertz
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Apr 2, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Reporting the event to relevant regulators
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.