HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICLowContained
THE HERTZ CORPORATION
bd_a4ca81d4d55c4b9b · schema v1 · pii pii-v1
Full breach record for THE HERTZ CORPORATION →The Hertz Corporation notified customers of a data breach involving its vendor, Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's platform in October and December 2024. Hertz confirmed the acquisition of data on February 10, 2025. Affected data includes names and contact information. Hertz engaged Kroll for identity monitoring and reported the incident to law enforcement.
California clockDiscovered Feb 10, 2025 → Notified Apr 11, 202560d ✓ CA 60-day OK9 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2c96b0a6f7ae2ca6Maine State AGfiled 2025-04-11Candidate
- bd_3f5803c2f674c4baWashington State AGfiled 2025-04-11Verified
- bd_88c1a4f18148e5caMontana State AGfiled 2025-04-11Verified
- bd_f5e59707561fd35bVermont State AGfiled 2025-04-11Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-601348
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 11, 2025
- Raw hash
- 6c44e9c0d4898d1427bd977b4b9922f00daf8d7725dbe2668a4712e8f2b437e8
Reporting entity
- Name
- THE HERTZ CORPORATIONnorm: the hertz
Victim entity
- Name
- THE HERTZ CORPORATIONnorm: the hertz
Incident
- Discovered
- Feb 10, 2025
- Materiality determined
- —
- Notification sent
- Apr 11, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- In the process of reporting the event to relevant regulators
- Third party
- via Cleo Communications US, LLC
- Initial access
- supply_chain
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 60d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 10, 2025→ Notified: Apr 11, 202560d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.