Skip to content

Hertz

Disclosed Apr 11, 20251 year ago1,222,756 affectedConfirmed

Official notice

Cleo zero-day breach exposes Hertz customers' licenses and card data

Hertz, which also owns Dollar and Thrifty, said customer data was stolen in an October to December 2024 attack on vendor Cleo, including driver's licenses, payment card data and workers' compensation claims; 96,665 Texans were affected.

What is known

People affected1,222,756 (as reported by the organization)
DisclosedApr 11, 2025
DiscoveredFeb 10, 2025
HappenedOct 27, 2024
AttackSupply chain
Data exposedNames, Government IDs, Health, Insurance, Credentials and tokens, Dates of birth, Phone numbers, Emails, Payment cards, Social Security numbers
SectorTransport · US
StatusConfirmed
Part ofCleo (2024)

Sources

Source
California Attorney General breach notice: Hertzoag.ca.gov · Official notice
Washington Attorney General breach notice: Hertzatg.wa.gov · Official notice
Notice letter filed with the Delaware DOJ: Hertzattorneygeneral.delaware.gov · Official notice
Oregon DOJ breach notice: Hertzjustice.oregon.gov · Official notice
Hertz says customers' personal data and driver's licenses stolen in data breachtechcrunch.com · News
Hertz confirms customer info, drivers' licenses stolen in data breachbleepingcomputer.com · News
Vermont Attorney General: 2025-04-11 The Hertz Corporation, on behalf of Hertz, Dollar, and Thrifty Data Breach Notice to Consumersago.vermont.gov · Official notice
Indiana Attorney General 2025 data breach report: Hertzin.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAApr 11, 2025
Washington AGresidents of WAApr 11, 202519,297
Delaware DOJresidents of DEApr 11, 20253,118
Oregon DOJresidents of ORApr 11, 20251,000,175
Vermont AGresidents of VTApr 11, 2025
Indiana AGresidents of INApr 11, 202512,307
ResearchtotalApr 14, 2025

Same campaign

History of this record
  • 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Report-2025.pdf · backfill source
  • 2026-09-25 · source: empty to https://ago.vermont.gov/document/2025-04-11-hertz-corporation-behalf-hertz-dollar-and-thrifty-data-breach-notice-consumers · backfill source
  • 2026-09-25 · campaign: empty to cleo-2024 · seed source
  • 2026-09-25 · sector: other to transport · seed source
  • 2026-09-25 · attack: hacking to supply-chain · seed source
  • 2026-09-25 · data_types: ["names","government-id","health","insurance","credentials"] to ["names","government-id","health","insurance","credentials","dob","phone","emails","payment-card","ssn"] · seed source
  • 2026-09-25 · summary: empty to Hertz, which also owns Dollar and Thrifty, said customer data was stolen in an October to December 2024 attack on vendor Cleo, including driver's licenses, payment card data and workers' compensation claims; 96,665 Texans were affected. · seed source
  • 2026-09-25 · title: empty to Cleo zero-day breach exposes Hertz customers' licenses and card data · seed source
  • 2026-09-25 · occurred: empty to 2024-10-27 · backfill source
  • 2026-09-25 · data_types: [] to ["names","government-id","health","insurance","credentials"] · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 1222756 · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · discovered: empty to 2025-02-10 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Hertz

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.