HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Avis Rent A Car System LLC
bd_c48d503b0f92f581 · schema v1 · pii pii-v1
Full breach record for Avis Rent A Car System LLC →Avis Rent A Car System LLC notified customers of a data breach where an unauthorized third party accessed a business application between August 3 and August 6, 2024. The company discovered the incident on August 5, 2024. Affected data included names and Social Security numbers. Avis engaged cybersecurity experts, contained the access, and is offering one year of Equifax credit monitoring.
California clockDiscovered Aug 5, 2024 → Notified Sep 4, 202430d ✓ CA 60-day OK4 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_1670f872c0bd111dMaine State AGfiled 2024-09-05Candidate
- bd_622c1b5d48ecfb48New Hampshire State AGfiled 2024-09-05Verified
- bd_741f7f632983b1a6Vermont State AGfiled 2024-09-05Verified
- bd_7c566134b6428716South Carolina State AGfiled 2024-09-05Verified
Show 4 more filings ↓Show fewer ↑
- bd_a4b54be72343d772Indiana State AGfiled 2024-09-05Verified
- bd_a7691d656072e585Oregon State AGfiled 2024-09-05Verified
- bd_d497f1d07a2c2a55Montana State AGfiled 2024-09-05Verified
- bd_f23bdac19fb73498Delaware State AGfiled 2024-09-05Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-591235
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2024
- Raw hash
- e2685e64a9e907637279a17bfd0858fc23f9608d98899004ddc102158e8d153c
Reporting entity
- Name
- Avis Rent a Car Canadanorm: avis rent a car canada
- Domain
- avis.ca
Victim entity
- Name
- Avis Rent A Car System LLCnorm: avis rent a car system
- Domain
- avis.com
Incident
- Discovered
- Aug 5, 2024
- Materiality determined
- —
- Notification sent
- Sep 4, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Alerted the relevant authorities
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 5, 2024→ Notified: Sep 4, 202430d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.