Data leak

Hertz Cleo MFT Clop Breach (100K+ Customers including Thrifty and Dollar)

πŸ“… 2024-12-01 🏒 Cleo Harmony; Cleo VLTrader; Cleo LexiCom πŸ”Ž CVE-2024-50623 Β· CVE-2024-55956
Primary Source β†—

Incident Details

Hertz Corporation disclosed in April 2025 that customer data had been stolen in attacks exploiting Cleo managed file transfer (MFT) software vulnerabilities in approximately December 2024 and January 2025. Clop confirmed responsibility for the Cleo MFT exploitation campaign. Data confirmed stolen included customer names, dates of birth, driver’s license numbers, credit card information, Social Security numbers, passport numbers, and Medicare/Medicaid identifiers. The breach affected Hertz brand customers and those from subsidiary brands Thrifty and Dollar. In Texas alone, over 96,000 notifications were filed; total affected individuals estimated at over 100,000. Hertz notified affected individuals starting April 11, 2025. Part of the broader Cleo MFT zero-day campaign by Clop that affected dozens of companies; see also 2024-12_cleo-mft-clop.yaml for the campaign-level entry.

Technical Details

Initial Attack Vector
Clop ransomware group exploited zero-day vulnerabilities in Cleo Harmony, VLTrader, and LexiCom managed file transfer software (CVE-2024-50623, CVE-2024-55956) to access Hertz's file transfer infrastructure
Vendor / Product
Cleo Harmony; Cleo VLTrader; Cleo LexiCom
CVE / GHSA References
CVE-2024-50623 CVE-2024-55956

Timeline

  1. 2024-12-01 Breach occurred
  2. 2025-04-11 Publicly disclosed
  3. 2025-04-11 Customers notified