Data of over 100 thousand customers was stolen from Hertz

17 April 2025 2 minutes Author: Newsman

Hackers have hacked the Cleo file-sharing platform, through which the personal data of at least 100 thousand Hertz users was leaked, including driver’s license numbers, social security and payment information. The company has already sent out notifications and offered personal protection services to the victims.

The attack took place in the fall of 2024, but Hertz only discovered the hack in February 2025. The hackers took advantage of a zero-day vulnerability in the Cleo platform, which the company uses for limited tasks. While Hertz’s internal network itself was not affected, data was stolen from third-party infrastructure related to file transfers.

According to official figures, at least 96,665 people in Texas and 3,409 in Maine were affected by the breach. Given Hertz’s scale as an international retailer, the total number of victims could exceed 100,000.

The stolen information included contact information, credit card details, driver’s licenses, ID documents, as well as insurance and compensation case data, including traffic accident data.

Cleo is a popular B2B file sharing platform used by large corporations. The same hack has previously affected WK Kellogg, Western Alliance Bank, and a number of other companies, including HPE and Thomson Reuters. In October 2024, the Clop group announced the exploitation of a vulnerability in Cleo, adding Hertz to the list of victims. Although Hertz representatives would not confirm the scale of the attack, independent analysts assume that it was a mass compromise. All victims received an offer of two-year personal protection through Kroll.

The Hertz incident is another example of how chain vulnerabilities in third-party software can turn into a large-scale data leak even with internal protection. Companies that rely on external services should not only regularly test their integrations, but also have a rapid response plan in case of an attack through partners.

Other related articles
News
Read more
Christopher Krebs leaves SentinelOne
Christopher Krebs left SentinelOne under pressure from the White House - an important precedent for the entire cyber industry. As a result of political pressure, the company lost access to state secrets, and Krebs himself decided to fight for his rights outside the company. This once again demonstrates that even in the field of cybersecurity, politics can put businesses at risk.
78
News
Read more
Dark Storm Attacks BreachForums
The BreachForums forum has again become the target of a cyberattack - this time by the Dark Storm Team, which carried out a DDoS attack "for fun", causing the resource to be unavailable in many countries. In parallel, rumors have arisen about the arrest of the IntelBroker hacker, but there is no official confirmation.
81
Found an error?
If you find an error, take a screenshot and send it to the bot.