Cybersecurity News Hub
No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
No Result
View All Result
Cybersecurity News Hub
No Result
View All Result
Home Data Breach

Cleo attack victim list grows as Hertz confirms customer data stolen – and security experts say it won’t be the last

Cyberinchief by Cyberinchief
December 1, 2025
Reading Time: 3 mins read
0
Cleo attack victim list grows as Hertz confirms customer data stolen – and security experts say it won’t be the last



Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.

In a statement confirming the incident, the firm said customer data was “acquired by an unauthorized party that we understand exploited zero-day vulnerabilities within Cleo’s platform in October 2024 and December 2024”.

“Hertz immediately began analyzing the data to determine the scope of the event and to identify individuals whose personal information may have been impacted,” the statement added.

RELATED POSTS

UK Hospital Asks Court to Stymie Ransomware Data Leak

These five countries recorded the most third-party data breaches last year

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

Customer data exposed in the breach may vary, the company said, but is believed to include customer names, contact information, dates of birth, credit card details, and information pertaining to driver’s licenses.

Similarly, a limited number of customers may have had US social security numbers or government ID information stolen in the breach.

“A very small number of individuals may have had their Social Security or other government identification numbers, passport information, Medicare or Medicaid ID (associated with workers’ compensation claims), or injury-related information associated with vehicle accident claims impacted by the event,” the company warned.

Hertz said it is yet to observe any “misuse of personal information” linked to the breach, but is offering customers two years of identity monitoring services. The company also advised customers to remain vigilant for potential fraudulent activity.

Sign up today and you will receive a free copy of our Future Focus 2025 report – the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives

Hertz the latest to disclose Cleo vulnerability impact

Hertz’ confirmation makes it the latest in a string of companies to have fallen victim to the Cleo breach. First disclosed last year, a vulnerability in the popular managed file transfer (MFT) service was pounced on by the Clop ransomware group.

Buy JNews
ADVERTISEMENT

The threat group initially claimed it had stolen data belonging to more than 60 companies as a result of the zero-day. This list has since grown, and earlier this year Western Alliance Bank confirmed it was among the growing list of victims.

Other confirmed victims include Chicago Public Schools, Champion Home Builders, and WK Kellogg.

Fresh research from ReliaQuest shows the impact of the Cleo breach will continue to grow for enterprises globally. Indeed, analysis by the security firm found the incident fueled a 23% increase in overall ransomware activity between Q4 and Q1 2025.

“Clop’s exploitation of Cleo highlights how weaknesses in systems can ripple across interconnected industries, disrupting supply chains, halting operations, and impacting countless businesses simultaneously,” the firm said in a blog post.

Rebecca Moody, head of data research at Comparitech, echoed this warning, noting that there’s likely to be “many more breach notifications from this exploit” as Clop has since added over 350 victims to its data leak site.

Dray Agha, senior manager of security operations at Huntress, said the incident underlines the “significant risks” posed by vulnerabilities in third-party platforms like Cleo.

“This highlights the importance of maintaining robust vulnerability management programs to identify and address security gaps in software promptly, especially those used for sensitive data transfer.”

Agha added the incident reflects a growing trend of cyber criminals targeting secure file transfer platforms. 2023, for example, saw a number of high-profile organizations impacted by the MOVEit data breach.

MORE FROM ITPRO

TOPICS

Ransomware

File Sharing



Source link

Tags: attackCleoConfirmscustomerdataExpertsgrowsHertzlistSecuritystolenvictimwont
ShareTweetPin
Cyberinchief

Cyberinchief

Related Posts

UK Hospital Asks Court to Stymie Ransomware Data Leak
Data Breach

UK Hospital Asks Court to Stymie Ransomware Data Leak

December 8, 2025
These five countries recorded the most third-party data breaches last year
Data Breach

These five countries recorded the most third-party data breaches last year

December 8, 2025
LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net
Data Breach

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

December 7, 2025
Rethinking the CIO-CISO Dynamic in the Age of AI
Data Breach

Rethinking the CIO-CISO Dynamic in the Age of AI

December 6, 2025
NHS supplier hit with £3m fine for security failings that led to attack
Data Breach

NHS supplier hit with £3m fine for security failings that led to attack

December 6, 2025
HHS Outlines AI Road Map Amid Major Department Overhaul
Data Breach

HHS Outlines AI Road Map Amid Major Department Overhaul

December 5, 2025
Next Post
Senior cyber crime garda warns of ‘alarming’ scale of child grooming within online gaming platforms

Senior cyber crime garda warns of 'alarming' scale of child grooming within online gaming platforms

How To Get In Cybersecurity? (Read The Description)

How To Get In Cybersecurity? (Read The Description)

Recommended Stories

Cyber Crime Police Shut Down iBomma and Bappam Websites | V6 News

Cyber Crime Police Shut Down iBomma and Bappam Websites | V6 News

November 18, 2025
What Is Firewall ? | Firewall Explained | Firewalls and Network Security | Simplilearn

What Is Firewall ? | Firewall Explained | Firewalls and Network Security | Simplilearn

October 27, 2025
How NASPO Helps U.S. State & Local Governments Battle Cybercrime

How NASPO Helps U.S. State & Local Governments Battle Cybercrime

November 13, 2025

Popular Stories

  • Allianz Life – 1,115,061 breached accounts

    Allianz Life – 1,115,061 breached accounts

    0 shares
    Share 0 Tweet 0
  • Prosper – 17,605,276 breached accounts

    0 shares
    Share 0 Tweet 0
  • साइबर अपराध | Illegal Payment Gateway & Rented Bank Accounts | MAMTA CHOPRA

    0 shares
    Share 0 Tweet 0
  • Miljödata – 870,108 breached accounts

    0 shares
    Share 0 Tweet 0
  • Snowflake Data Breach Explained: Lessons and Protection Strategies

    0 shares
    Share 0 Tweet 0

Search

No Result
View All Result

Recent Posts

  • Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026
  • Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
  • Polisi kembali ungkap sindikat Cyber Crime kejahatan Internasional – iNews Malam 09/03

Categories

  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos

Newsletter

© 2025 All rights reserved by cyberinchief.com

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us

© 2025 All rights reserved by cyberinchief.com

Newsletter Signup

Subscribe to our weekly newsletter below and never miss the latest News.

Enter your email address

Thanks, I’m not interested