The Hertz Corporation issued a supplemental breach notification to Delaware regarding a cybersecurity incident involving third-party vendor Cleo Communications US, LLC. On February 10, 2025, Hertz confirmed that an unauthorized third party exploited zero-day vulnerabilities in Cleo's file transfer platform in late 2024 to acquire Hertz data. The incident involved customer contact information. Hertz reported the event to law enforcement, engaged Kroll for two years of identity monitoring, and is notifying relevant regulators.