Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Top 10 DNS Security Solutions for 2026
August 1, 2026
Critical Flaw in Google Ad Manager Exploited to Deliver Crypto-Stealing Malware
August 1, 2026
Best Cloud Firewall Solutions: Top 10 for 2026
August 1, 2026
Home/Breaches/Hertz Data Breach – Customer Personal Information Stolen by Hackers
Breaches

Hertz Data Breach – Customer Personal Information Stolen by Hackers

Hertz Data Breach: Customer Personal Data Stolen by Okay, so Hertz Corporation? Yeah, they’ve just confirmed a pretty big data breach. It’s impacting customers across their Hertz, Dollar,...

Jennifer sherman
Jennifer sherman
January 1, 2026 2 Min Read
112 0

Hertz Data Breach: Customer Personal Data Stolen by

Okay, so Hertz Corporation? Yeah, they’ve just confirmed a pretty big data breach. It’s impacting customers across their Hertz, Dollar, and Thrifty brands. Basically, hackers managed to exploit some critical security vulnerabilities, getting their hands on sensitive customer information.

The company disclosed that unauthorized third parties acquired customer data after exploiting zero-day vulnerabilities in a vendor’s file transfer platform, potentially exposing the personal details of an undisclosed number of customers.

How Hackers Gained Access

According to a recent notice of data incident, Hertz discovered on February 10, 2025, that customer data had been compromised through its vendor, Cleo Communications US, LLC.

The hackers exploited zero-day vulnerabilities within Cleo’s file transfer platform during two separate incidents in October and December 2024.

“The unauthorized access was facilitated through critical security flaws that were previously unknown to the software developers,” said cybersecurity expert Marcus Reynolds, who specializes in transportation sector security breaches.

“Zero-day vulnerabilities are particularly dangerous as they can be exploited before vendors have an opportunity to develop and distribute patches.”

Following a comprehensive data analysis completed on April 2, 2025, Hertz confirmed that the compromised information includes customers’ names, contact information, dates of birth, credit card details, and driver’s license information. The breach also exposed data related to workers’ compensation claims.

A smaller subset of individuals may have had more sensitive information compromised, including Social Security numbers, government identification numbers, passport information, Medicare or Medicaid IDs associated with workers’ compensation claims, and injury-related information connected to vehicle accident claims.

Hertz’s Data Breach Response

In response to the breach, Hertz has taken several remedial measures. The company has confirmed that Cleo has investigated the incident and addressed the identified vulnerabilities.

Additionally, Hertz has reported the incident to law enforcement and is working with relevant regulatory authorities. “We take the privacy and security of personal information seriously,” stated a Hertz representative.

“While we are not aware of any misuse of personal information for fraudulent purposes in connection with this event, we are providing resources to help customers protect themselves.”

As part of its response plan, Hertz has partnered with Kroll, a risk consulting firm, to provide affected U.S. residents with two years of complimentary identity monitoring or dark web monitoring services.

Cybersecurity analysts have noted that this breach follows a growing trend of attacks targeting third-party vendors to gain access to larger corporations’ data.

Affected customers are advised to remain vigilant by regularly reviewing account statements and monitoring credit reports for unauthorized activity.

Industry experts recommend that affected individuals consider placing fraud alerts or credit freezes on their credit files as additional precautionary measures to protect against potential identity theft or fraud resulting from the data breach.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCybersecurityExploitHackerPatchSecurityzero-day

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

CISA Warns of Gladinet CentreStack and Triofox Vulnerability Exploited in Attacks

Next Post

TikTok Breach Exposes 900K Usernames & Hackers Allegedly

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Keycloak CVE-2024-3700 Exposes User Data Across Admin Boundaries
July 31, 2026
CyberStrike: AI Platform Automates Penetration Testing
July 31, 2026
Critical JetBrains TeamCity CVE-2024-27198 Remote Code Execution Flaw Patched
July 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us