logo

More than 100,000 had information stolen from Hertz through Cleo file share tool

ID: 6da0a243-ce85-5917-8632-148a3f91e6cf

STIX ID: report--6da0a243-ce85-5917-8632-148a3f91e6cf

Feed Name: The Record from Recorded Future News

Threat Score
78/100

Date Published: 2025-04-16

Date Updated: 2026-05-01

...
...

Hertz disclosed that unauthorized actors exploited zero-day vulnerabilities in the Cleo file-sharing platform in October and December 2024 to acquire sensitive customer and employee data — including Social Security numbers, driver’s licenses, payment card information, and medical/claims details. The company notified multiple U.S. states, is offering identity protection services, and the incident appears linked to a wider exploitation campaign (named by the Clop ransomware group) that affected numerous other organizations and potentially tens of thousands of individuals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.