THE HERTZ CORPORATION
bd_ac4d00b21e3d316a · schema v1 · pii pii-v1
Full breach record for THE HERTZ CORPORATION →3 incidents on fileHertz Corporation notified NH AG of a privacy event involving vendor Cleo Communications. Unauthorized third parties exploited zero-day vulnerabilities (CVE-2024-50623, CVE-2024-55956) in Cleo's file transfer platform in Oct/Dec 2024. Hertz confirmed data acquisition on Feb 10, 2025. ~4,657 NH residents affected (PII). Notifications sent April 11, 2025, including 2 years of Kroll identity monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 1, 2024
Begins
Feb 10, 2025
Discovered
Apr 14, 2025
Filed
vs. sector median
+2 wks slower
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- Rhode Island State AGbd_82f3b7bd9ca1832e2025-04-14Verified
- Maine State AGbd_2c96b0a6f7ae2ca62025-04-11 · +3dCandidate
- Washington State AGbd_3f5803c2f674c4ba2025-04-11 · +3dVerified
- Montana State AGbd_88c1a4f18148e5ca2025-04-11 · +3dVerified
Show 5 more filings ↓Show fewer ↑up to 13d gap
- California State AGbd_a4ca81d4d55c4b9b2025-04-11 · +3dVerified
- Delaware State AGbd_bae3ed4100ea194a2025-04-11 · +3dVerified
- Nebraska State AGbd_d6a8b36608cf60032025-04-11 · +3dVerified
- Vermont State AGbd_f5e59707561fd35b2025-04-11 · +3dVerified
- Illinois State AGbd_b3aa3f6351a7be422025-04-01 · +13dVerified
Filing propagation · 10 filings · 10 states
View merged incident ↗Pattern: first filing Apr 1 (IL), last Apr 14 (NH) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.