HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICLowContained
THE HERTZ CORPORATION
bd_f5e59707561fd35b · schema v1 · pii pii-v1
Full breach record for THE HERTZ CORPORATION →The Hertz Corporation notified consumers of a data breach involving its vendor, Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in October and December 2024 to acquire Hertz data. Hertz reported the incident to law enforcement and engaged Kroll to provide two years of complimentary identity monitoring services to affected individuals.
Vermont clock⏱ VT AG >14 bday9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2c96b0a6f7ae2ca6Maine State AGfiled 2025-04-11Candidate
- bd_3f5803c2f674c4baWashington State AGfiled 2025-04-11Verified
- bd_88c1a4f18148e5caMontana State AGfiled 2025-04-11Verified
- bd_a4ca81d4d55c4b9bCalifornia State AGfiled 2025-04-11Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-04-11-hertz-corporation-behalf-hertz-dollar-and-thrifty-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 11, 2025
- Raw hash
- 96d881f9a2bfd6209af6d9d48f2d590d040392a48139bbc67bb194b96afdeafa
Reporting entity
- Name
- THE HERTZ CORPORATIONnorm: the hertz
Victim entity
- Name
- THE HERTZ CORPORATIONnorm: the hertz
Incident
- Discovered
- Feb 10, 2025
- Materiality determined
- —
- Notification sent
- Apr 11, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Reported this event to law enforcementIn the process of reporting the event to relevant regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.