This week car rental company Hertz notified its users of a wide-ranging data breach that exposed some customers' personal information.
On Monday, April 14, TechCrunch reported the appearance of a Notice of Data Incident on the Hertz website. According to the notice, personal information including names, contact information, date of birth, credit card information, driver's license information, and "information related to workers' compensation claims" were potentially exposed in the data breach through an external vendor named Cleo.
Additionally, Social Security numbers, government IDs, passport information, Medicare or Medicaid IDs, and medical information from car accident claims may also have been stolen from "a very small number of individuals," said the notice.
Hertz discovered the breach on February 10, and customer data was stolen in October 2024 and December 2024.
The notice did not say how many customers had their personal information exposed. However, according to a copy of the notice issued to Maine residents (published by the Office of the Maine Attorney General), the breach affected 3,409 customers in Maine alone. That means the true number of impacted individuals is likely far larger, especially considering that notices were also issued to customers in Australia, Canada, New Zealand, the United Kingdom, and beyond.
A spokesperson for Hertz declined to share specific numbers but said "it would be inaccurate to say millions of customers are affected."
The breach came from a Hertz vendor called Cleo, which manages file-sharing platforms for the company. "On February 10, 2025, we confirmed that Hertz data was acquired by an unauthorized third party that we understand exploited zero-day vulnerabilities within Cleo’s platform in October 2024 and December 2024," read the notice. Hertz didn't provide any further specifics about the hack or hackers, but during those same months, cybersecurity firm Huntress reported "evidence of threat actors exploiting this [Cleo software]." Around that same time, ransomware group Clop claimed responsibility for data theft attacks targeting Cleo's servers.
In the notice, Hertz said it was "not aware of any misuse of personal information for fraudulent purposes in connection with the event." But it encouraged customers to "remain vigilant" of any instances of data breaches and shared resources on how to monitor account statements and credit reports, including how to place a fraud alert or credit freeze on their accounts. Some Hertz customers will also be offered "two years of identity monitoring services" free of charge.
UPDATE: Apr. 15, 2025, 5:30 p.m. EDT This story has been updated with new information from a Hertz representative.
Copyright © 2023 Powered by
Hertz customer data stolen in cybersecurity breach (updated)-鼓盆之戚网
sitemap
文章
8129
浏览
68326
获赞
6392
Hackers forced the New Zealand stock exchange to shut down... twice
A distributed denial-of-service attack may not be sophisticated, but it sure is effective. That muchTinder will give 500 lucky matches free COVID tests
With the United States finally turning a corner with the coronavirus pandemic, singles are taking to‘QAnon Shaman’ is seen leading the charge as pro
When supporters of Donald Trump stormed the U.S. Capitol Hill on Wednesday afternoon, a face familiaThe year of the beep: How car horns became the rallying cry of 2020
Before 2020 I hated the sound of car horns.Honking is often associated with road rage or used to warThe 7 best Tumblr scams of all time
It’s Cheat Week at Mashable. Join us as we take a look at how liars, scammers, grifters, and eHave a home office? You need these accessories.
Essentials Week spotlights unexpected items that make our daily lives just a little bit better.My moHow to disable Instagram embeds (and why you should)
After a push by the National Press Photographers Association (NPPA) and the American Society of MediFacebook, let me unlike this
As a teenager on Facebook, I liked any page I could get my grubby hands on when it was my turn to usChemistry Nobel awarded to developers of lithium
Three scientists have been awarded the Nobel Prize in Chemistry for their development of lithium-ion'Disaster Girl' meme NFT sells for $500,000 at auction
The trend of outrageous NFT auction sales continues with the sale of the "Disaster Girl" NFT, whichTesla issues recall for nearly 54,000 vehicles due to rolling stop feature
Tesla is issuing a recall of 53,822 vehicles in the U.S. due to an experimental feature that may beHow to disable Instagram embeds (and why you should)
After a push by the National Press Photographers Association (NPPA) and the American Society of MediFacebook tries to warn users about Apple 'tax,' Apple says no
Apple and Facebook are clashing heads again. Facebook recently tried to inform its users that AppleGoFundMe blasts inaction on COVID relief by sharing people's stories
Even GoFundMe thinks that people shouldn't have to depend on GoFundMe during the pandemic.The crowdfParents track kids with Life360 for free. Life360 then sells their data.
Life360, a popular family safety app used by 33million people worldwide, has been marketed as a grea