logo

Hertz Falls Victim to Cleo Zero-Day Attacks

ID: eb0e8b2d-ed59-5dce-8f38-05a261e403f9

STIX ID: report--eb0e8b2d-ed59-5dce-8f38-05a261e403f9

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-04-15

Date Updated: 2026-05-05

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

Hertz confirmed that some customer data was stolen after threat actors (attributed to the Clop ransomware gang) exploited zero-day vulnerabilities in Cleo Communications' managed file-transfer platform in Oct and Dec 2024; Hertz, Dollar and Thrifty are issuing breach notifications and the compromised data may include names, contact details, dates of birth, payment card and driver’s license information and, for a subset, government IDs and medical/claims data. Clop claims to have stolen data from dozens of companies during a mass-exploitation campaign targeting multiple Cleo products, and while no misuse has been confirmed, impacted individuals are advised to monitor accounts and credit reports.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.