THE HERTZ CORPORATION
bd_4d9936b8024bb49a · schema v1 · pii pii-v1
Full breach record for THE HERTZ CORPORATION →3 incidents on fileHertz Corporation notified Delaware AG of a supply-chain breach involving vendor Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in Oct/Dec 2024 to exfiltrate data. Hertz confirmed the scope on April 2, 2025. Over 1.6 million individuals affected, including 6,647 Delaware residents. Data included SSNs, driver's licenses, financial account numbers, and medical history. Hertz engaged Kroll for identity monitoring and reported to law enforcement.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Jun 24, 2024
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.