Data leak
Hertz Cleo MFT Clop Breach (100K+ Customers including Thrifty and Dollar)
Primary Source βIncident Details
Hertz Corporation disclosed in April 2025 that customer data had been stolen in attacks exploiting Cleo managed file transfer (MFT) software vulnerabilities in approximately December 2024 and January 2025. Clop confirmed responsibility for the Cleo MFT exploitation campaign. Data confirmed stolen included customer names, dates of birth, driver’s license numbers, credit card information, Social Security numbers, passport numbers, and Medicare/Medicaid identifiers. The breach affected Hertz brand customers and those from subsidiary brands Thrifty and Dollar. In Texas alone, over 96,000 notifications were filed; total affected individuals estimated at over 100,000. Hertz notified affected individuals starting April 11, 2025. Part of the broader Cleo MFT zero-day campaign by Clop that affected dozens of companies; see also 2024-12_cleo-mft-clop.yaml for the campaign-level entry.
Technical Details
- Initial Attack Vector
- Clop ransomware group exploited zero-day vulnerabilities in Cleo Harmony, VLTrader, and LexiCom managed file transfer software (CVE-2024-50623, CVE-2024-55956) to access Hertz's file transfer infrastructure
- Vendor / Product
- Cleo Harmony; Cleo VLTrader; Cleo LexiCom
- CVE / GHSA References
- CVE-2024-50623 CVE-2024-55956
Timeline
- 2024-12-01 Breach occurred
- 2025-04-11 Publicly disclosed
- 2025-04-11 Customers notified