[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2kksydo51b52n":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":18,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":34,"seoTitle":35,"seoTitleEn":8,"seoDescription":35,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"6a71cc08c182201d633a2933","HertzCleo2024","Hertz 2024 Data Breach","hertz-cleo-2024","hertz.com","2024-10-01T00:00:00.000Z","2026-08-04T11:24:55.778Z","The Hertz Corporation data incident notice","https:\u002F\u002Fwww.hertz.com\u002Fcontent\u002Fdam\u002Fhertz\u002Fglobal\u002Fresources\u002FNotice_of_Data_Incident-United_States.pdf",[14,16,17],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhertz-confirms-customer-info-drivers-licenses-stolen-in-data-breach\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fhertz-discloses-data-breach-linked-to-cleo-hack\u002F",null,"unknown","people","Unknown",[23,24,25,26,27,28,29,30,31,32,33],"Names","Contact information","Dates of birth","Driver's licenses","Credit card information","Workers' compensation claims","Social Security numbers","Government-issued IDs","Passport information","Medicare\u002FMedicaid IDs","Injury information","\u003Cp>\u003Cstrong>The 2024 Hertz data breach\u003C\u002Fstrong> was a third-party incident caused by exploitation of zero-day vulnerabilities in a Cleo file-transfer platform that Hertz used for limited purposes. Hertz confirmed that an unauthorized party acquired company data through Cleo in October and December 2024.\u003C\u002Fp>\u003Cp>Because the exact first-access day was not disclosed, the catalog uses October 2024 month precision. Hertz confirmed the acquisition on February 10, 2025, and completed its review on April 2.\u003C\u002Fp>\u003Ch2>What information was affected?\u003C\u002Fh2>\u003Cp>The information varies by individual. Hertz says it may include names, contact details, dates of birth, driver's-license information, credit-card information, and workers' compensation claim details.\u003C\u002Fp>\u003Cp>A smaller group may have had Social Security numbers or other government identifiers involved. A very small number may also have had passport information, Medicare or Medicaid IDs, or injury information associated with vehicle-accident claims affected. The incident involved customers of the Hertz, Dollar, and Thrifty brands.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>Hertz has not disclosed a global unique affected-person total. The 3,409 people reported to Maine represent notification recipients in that state only and are not used as the overall count.\u003C\u002Fp>\u003Ch2>How did Hertz respond?\u003C\u002Fh2>\u003Cp>The company stopped using the affected Cleo service, notified law enforcement and relevant regulators, and offered affected people two years of identity-monitoring services. Hertz says it found no evidence that its own network was affected.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should monitor payment cards and financial accounts, review credit reports, and report unfamiliar activity promptly. People whose driver's-license or identity-document information was involved should follow the country-specific steps in their notice.\u003C\u002Fp>","","Hertz's 2024 Cleo breach affected customer and identity information. Review the confirmed scope, response, and practical safeguards.","\u002Fuploads\u002Flogo\u002Fhertz-corporation-official.svg",false,{"name":40,"sector":41,"country":42,"website":43,"websiteArchiveUrl":35,"websiteStatus":35,"websiteCheckedAt":18},"The Hertz Corporation","Transportation","United States","https:\u002F\u002Fwww.hertz.com\u002F"]