Hertz Corporation, the well-known rental car company, has confirmed that it was the target of a data breach tied to a previously unknown vulnerability.

The attack affected customers of not only Hertz itself, but also its Thrifty and Dollar rental brands.
According to a notice shared with regulators, unauthorized access to personal data was confirmed on February 10, 2025.
The attackers are believed to have exploited security holes in file transfer software developed by Cleo. Those exploits occurred back in October and December 2024, long before the breach was officially identified.
The stolen data varies by individual but may include personal details such as full names, contact info, birthdates, credit card data, and driver’s license numbers. Some records even contained highly sensitive information.
Sensitive Customer Information at Risk
Hertz says that for most customers, the stolen data may be limited to basic contact details. However, in more serious cases, the stolen files may also include:
- Social Security Numbers
- Government-issued IDs
- Passport details
- Medicare or Medicaid ID numbers
- Injury-related information from vehicle accident claims
The breach has raised concerns, especially for those whose data is connected to workers’ compensation claims. Even though the company says only a small group of people had this level of exposure, the presence of such personal details means the risk of identity fraud is higher than usual.
How Many People Were Affected?
So far, Hertz has not confirmed a total number of victims. However, some insight comes from required reporting to states. For example, the Maine Attorney General’s Office shows that at least 3,409 residents in that state received official breach notifications.
Hide Your Digital Fingerprint
Notifications have also been sent in California and Vermont, but those states haven’t shared specific numbers yet. This suggests the total number of impacted individuals is likely much higher.
Clop Ransomware Group Claims Responsibility
The group behind this attack is known as Clop, also called TA505. These cybercriminals have shifted from ransomware to large-scale data theft operations over the last few years.
Back in October 2024, Clop exploited zero-day flaws in several of Cleo’s secure file transfer tools, including Cleo Harmony, VLTrader, and LexiCom.
After the breach, Clop added Hertz to its public extortion site, claiming they had stolen files and would leak them if a payment wasn’t made.

Hertz isn’t the only company caught up in these attacks. Others investigating similar breaches include Western Alliance Bank, WK Kellogg Co, and Sam’s Club. In total, Clop claims to have targeted data from 66 organizations.
Clop is no stranger to these types of attacks. They’ve previously gone after other popular secure file transfer platforms like MOVEit Transfer, GoAnywhere MFT, SolarWinds Serv-U, and Accellion FTA.
The group’s playbook is simple: find a weakness in file transfer software, grab as much data as possible, and then threaten to release it unless a company pays a ransom. In many cases, the data still leaks, even after payment.
What Hertz Is Doing Now
Hertz says there’s no current evidence that the stolen data has been used for fraud. Still, they are offering two years of free identity monitoring to affected customers.
They’re also urging people to stay alert for unfamiliar credit card activity, suspicious emails or phone calls, and signs of identity theft.
The company has not disclosed how they plan to strengthen data security going forward, but this incident may push many businesses to re-evaluate their use of third-party file sharing platforms.
Exclusive Surfshark Discount
Your online activity is currently monitored by your ISP, app/addon/IPTV developers, government agencies, and the websites you visit.
- Become 100% anonymous while streaming and downloading.
- Use on Unlimited Devices & share 1 account with the entire family.
- Save 85% with the 24-Month Plan + Get 3 FREE Months.
Final Thoughts
If you’ve rented from Hertz, Thrifty, or Dollar within the past few years, keep an eye on your accounts. Even if you haven’t received a notification yet, the breach may still affect you.
Be cautious with emails requesting personal information and consider freezing your credit if you think your Social Security number was involved. It’s always better to act early than wait until you’re a victim of fraud.
For more information on this story, refer to Hertz’s data breach notification (PDF) and the report from BleepingComputer.
We want to know your thoughts. What do you think about this story? Let us know in the comment section below!
Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.
This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.




