THE HERTZ CORPORATION
ent_019e20923a9965d4321f815d777fca62
Disclosures
12
State AG · 10 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,613,773
nationwide · State AG DE
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- THE HERTZ CORPORATION
- Normalized
- the hertz— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300PD0C69OJ0NLB27
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- HERTZ CORP— per SEC Exhibit 21 filing
Disclosure history (12)newest first
- Rhode Island State AGas victim2025-04-14
The Hertz Corporation notified the Rhode Island Attorney General of a privacy event involving its vendor, Cleo Communications US LLC. An unauthorized third party exploited zero-day vulnerabilities (CVE-2024-50623, CVE-2024-55956) in Cleo's file transfer platform in October and December 2024, acquiring Hertz data. The incident affected approximately 4,123 Rhode Island residents, exposing names, contact info, DOB, payment card data, driver's license info, and workers' comp/Medicare data. Hertz reported the event to law enforcement, engaged Kroll for two years of identity monitoring, and began notifying affected individuals on April 11, 2025.
- New Hampshire State AGas victim2025-04-14
Hertz Corporation notified NH AG of a privacy event involving vendor Cleo Communications. Unauthorized third parties exploited zero-day vulnerabilities (CVE-2024-50623, CVE-2024-55956) in Cleo's file transfer platform in Oct/Dec 2024. Hertz confirmed data acquisition on Feb 10, 2025. ~4,657 NH residents affected (PII). Notifications sent April 11, 2025, including 2 years of Kroll identity monitoring.
- Maine State AGas victim2025-04-11
The Hertz Corporation reported a third-party supply chain breach involving vendor Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in October and December 2024. Hertz discovered the incident on February 10, 2025, and notified affected individuals on April 11, 2025. The breach impacted customer contact information. 3,409 Maine residents were affected. Hertz engaged Kroll to provide two years of identity monitoring services.
- Washington State AGas victim2025-04-11
The Hertz Corporation notified Washington AG of a breach involving vendor Cleo Communications US LLC. An unauthorized third party exploited zero-day vulnerabilities (CVE-2024-50623, CVE-2024-55956) in Cleo's file transfer platform in Oct/Dec 2024. Hertz confirmed data acquisition on Feb 10, 2025. ~19,297 Washington residents affected. Data included names, DOB, payment card info, driver's licenses, and SSNs. Notifications began April 11, 2025, including 2 years of Kroll identity monitoring.
- Montana State AGas victim2025-04-11
Hertz Corporation notified Montana residents of a data breach involving vendor Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in Oct/Dec 2024 to acquire Hertz data. Hertz confirmed the incident on Feb 10, 2025, and is offering two years of identity monitoring via Kroll. Personal information including names and contact info was potentially impacted.
- California State AGas victim2025-04-11
The Hertz Corporation notified customers of a data breach involving its vendor, Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's platform in October and December 2024. Hertz confirmed the acquisition of data on February 10, 2025. Affected data includes names and contact information. Hertz engaged Kroll for identity monitoring and reported the incident to law enforcement.
- Delaware State AGas victim2025-04-11
The Hertz Corporation notified individuals of a data breach involving its third-party vendor, Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in October and December 2024 to acquire Hertz data. Hertz confirmed the incident on February 10, 2025, and engaged Kroll to provide two years of identity monitoring services. The breach potentially exposed customer names, contact information, and government identifiers.
- Nebraska State AGas victim2025-04-11
The Hertz Corporation notified Nebraska AG of a privacy event involving vendor Cleo Communications US LLC. An unauthorized third party exploited zero-day vulnerabilities (CVE-2024-50623, CVE-2024-55956) in Cleo's file transfer platform in Oct/Dec 2024. Hertz confirmed data acquisition on Feb 10, 2025. Impact includes names, DOB, payment card, driver's license, and some SSN/health data. Notifications began April 11, 2025, including Kroll identity monitoring services.
- Vermont State AGas victim2025-04-11
The Hertz Corporation notified consumers of a data breach involving its vendor, Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in October and December 2024 to acquire Hertz data. Hertz reported the incident to law enforcement and engaged Kroll to provide two years of complimentary identity monitoring services to affected individuals.
- Illinois State AGas victim2025-04-01
THE HERTZ CORPORATION filed a data-breach notice with the Illinois Attorney General in April 2025 (case 25-04-101). The register records the breach as discovered on February 10, 2025. Personal information types reported: drivers license, financial account number, medical information, ssn. Additional entities named: CLEO COMMUNICATIONS US LLC. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Delaware State AGas victim2024-06-24
Hertz Corporation notified Delaware AG of a supply-chain breach involving vendor Cleo Communications US, LLC. An unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in Oct/Dec 2024 to exfiltrate data. Hertz confirmed the scope on April 2, 2025. Over 1.6 million individuals affected, including 6,647 Delaware residents. Data included SSNs, driver's licenses, financial account numbers, and medical history. Hertz engaged Kroll for identity monitoring and reported to law enforcement.
- New Hampshire State AGas victim2012-08-01
The Hertz Corporation notified the NH AG of a potential breach involving a third-party vendor, JP Morgan. Unauthorized access to Order-to-Pay servers exposed names, addresses, SSNs, and bank account numbers of suppliers, consultants, and employees. 8 NH residents were affected. Notices were to be mailed by Aug 3, 2012.