Hertz Says Customers’ Personal Data and Driver’s Licenses Stolen in Data Breach
The Car Rental Giant Attributed the Breach to Cleo, Whose Customers Had Data Stolen by a Ransomware Gang in
Hertz Says Customers’ Personal Data and Driver’s Licenses Stolen in Data Breach
Car Rental Giant Hertz Hert Begun Nots Its Customers of A Data Breach That Included Their Personal Information and Driver’s Licenses.
The Rental Company, Which Also Owns the Dollar and Thrifty Brands, Said in Notices on Its Website that the Breach Relaps to a Cyberattack on One of Its Between October 2024 and December 2024.
The Stolen Data Varies by Region, But Largely Includes Hertz Customer Names, Dates of Birdth, Contact Information, Driver’s Licenses, Payment Card Information, and Workers’ Compension Claims. Hertz Said A Smaller Number of Customers Had Their Social Security Numbers in the Breach, Along With OTher Government-ISSUED
Notices on Hertz’s Website DiscLoSed the Breach to Customers in Australia, Canada, The Europe Union, New Zealand, and The United Kingdom.
Hertz Also DiscloSed the Breach with Several Us States, Inclument California and Maine. Hertz Said at Least 3,400 Customers in Mainine Were Affpeded But Noting List The Total Number of Affacted Indigitals, Who is Likely to Be Significantly Higher.
Emily Spencer, A SpoKepersonon for Hertz, Would Not Provide Techcrunch
The Company Attributed the Breach to a Vendor, Software Maker Cleo, Who Last Year Was at the Center of A Mass-Hacking Campaign by A Prlyific Russia-Linked Ransomware Gang.
Hertz is one of the Dozens of Companies that USED Cleo’s Software at the Time of the Data Thefts. The Clop Ransomware Gang Claimed Last Year To Have Exploited A Zero-Daya Vulnerability in Cleo’s Widly Used Enterprise File Transfer Products, Who Allow Allow Companies to Share Large Sets of Sensitive The Internet. By Breaching these Systems, The Hackers Stole Reams of Data from Cleo’s Corporate Customers.
Soon After, The Clop Ransomware Gang Claimed on Its Dark Web Leak Site that it stole data from Close to 60 Companies By Explosing the Bug In their Cleo Systems. In A Later Post, Clop Claimed Dozens More Alleged Corporate Victims.
The Data Extortion Campaign Became One of the Most Notable Mass-Hacks of 2024.
At the Time, Hertz, Who Was Named on Clop’s Site, Said it Had Him No Evidence ”That Hertz Data Ortz Systems were Affpeded.
On Monday, Hertz’s Spokeperson Told Techcrunch it Found No Evidence that Hertz’s Own Network. Vulnerabilities with Cleo’s platform in October 2024 and December 2024. ”
A Cleo Executive Did Not Respond to Techcrunch’s Inquiry On Monday.