THE HERTZ CORPORATION
bd_f5e59707561fd35b · schema v1 · pii pii-v1
Full breach record for THE HERTZ CORPORATION →3 incidents on fileThe Hertz Corporation notified consumers of a data breach involving its vendor, Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in October and December 2024 to acquire Hertz data. Hertz reported the incident to law enforcement and engaged Kroll to provide two years of complimentary identity monitoring services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Oct 1, 2024
Begins
Feb 10, 2025
Discovered
Apr 11, 2025
Filed
vs. sector median
+1 wks slower
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- Maine State AGbd_2c96b0a6f7ae2ca62025-04-11Candidate
- Washington State AGbd_3f5803c2f674c4ba2025-04-11Verified
- Montana State AGbd_88c1a4f18148e5ca2025-04-11Verified
- California State AGbd_a4ca81d4d55c4b9b2025-04-11Verified
Show 5 more filings ↓Show fewer ↑up to 10d gap
- Delaware State AGbd_bae3ed4100ea194a2025-04-11Verified
- Nebraska State AGbd_d6a8b36608cf60032025-04-11Verified
- Rhode Island State AGbd_82f3b7bd9ca1832e2025-04-14 · +3dVerified
- New Hampshire State AGbd_ac4d00b21e3d316a2025-04-14 · +3dVerified
- Illinois State AGbd_b3aa3f6351a7be422025-04-01 · +10dVerified
Filing propagation · 10 filings · 10 states
View merged incident ↗Pattern: first filing Apr 1 (IL), last Apr 14 (NH) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.