HackingTargetedIDENTITY_BASICLowContained
Avis Rent A Car System LLC
bd_741f7f632983b1a6 · schema v1 · pii pii-v1
Full breach record for Avis Rent A Car System LLC →Avis Rent A Car System, LLC disclosed a data breach where an unauthorized third party accessed a business application between August 3-6, 2024. The incident compromised names and other personal data. The company engaged cybersecurity experts, alerted authorities, and offered one year of Equifax credit monitoring to affected individuals.
Vermont clock⏱ VT AG >14 bday4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_1670f872c0bd111dMaine State AGfiled 2024-09-05Candidate
- bd_622c1b5d48ecfb48New Hampshire State AGfiled 2024-09-05Verified
- bd_7c566134b6428716South Carolina State AGfiled 2024-09-05Verified
- bd_a4b54be72343d772Indiana State AGfiled 2024-09-05Verified
Show 4 more filings ↓Show fewer ↑
- bd_a7691d656072e585Oregon State AGfiled 2024-09-05Verified
- bd_c48d503b0f92f581California State AGfiled 2024-09-05Verified
- bd_d497f1d07a2c2a55Montana State AGfiled 2024-09-05Verified
- bd_f23bdac19fb73498Delaware State AGfiled 2024-09-05Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-09-05-avis-budget-group-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2024
- Raw hash
- c1c07d60347b96e44968a5f02a51070f66510f3836fa7de6db9484addb2f6ce3
Reporting entity
- Name
- Avis Rent a Car Canadanorm: avis rent a car canada
- Domain
- avis.ca
Victim entity
- Name
- Avis Rent A Car System LLCnorm: avis rent a car system
- Domain
- avis.com
Incident
- Discovered
- Aug 5, 2024
- Materiality determined
- —
- Notification sent
- Sep 5, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- alerted the relevant authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.