Desk live·
ForensicPost
Breaches/Disclosure/File 25-0403

Hertz Confirms Customer and Employee Data Taken Through Cleo Flaw

Hertz confirmed that customer and employee data had been taken through the Cleo flaw. The intrusion was in October and December; the company finished working out what happened on 2 April.

Constructed geometry · not a chart of case data
JurisdictionUSAEstero, Floridathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetHertz
ActorCl0p
S. Rosler12 min readConfidence: medium3 sources reviewed

Hertz confirmed in April 2025 that data belonging to customers and employees had been exfiltrated through the Cleo file-transfer vulnerabilities, in unauthorised access reported to have occurred in two waves, in October and December 2024.

The company completed its internal investigation on 2 April 2025. The interval between the first wave and that conclusion is around six months.

Six Months Is Not A Scandal, And It Is Worth Stating Why

The company did not hold the compromised product. A supplier’s software was exploited, data belonging to the company was taken from it, and establishing whose records were in the extracted files is work that has to be done record by record.

This corpus has recorded that shape repeatedly — at 25-0210, where nearly three million people were notified the year after the event, and across the supplier-compromise files. The delay is structural, and treating it as negligence obscures where the actual failure sat.

The Disclosure Exists Because The Company Is Listed

The routes into the public record set out at 25-0502 and extended at 25-0924b include a securities listing, and this is a clean instance. A privately held car rental operator using the same product would have had the same exposure and, quite possibly, produced no public record at all.

That is the observation the corpus keeps making and it should be uncomfortable each time: the incidents this database contains are disproportionately the incidents that happened to companies with an obligation to say so.

What Is Not Established Here

How many people were affected. Reporting at the time described categories of data rather than counts, and this desk has not seen a figure it would print.

The corpus writes "Not established" in a case card rather than guessing, and this file carries several. A file that reported a number here would be reporting an estimate somebody else made.

How we reported this

Compiled from contemporaneous reporting of Hertz’s confirmation, listed below. The two-wave characterisation and the 2 April investigation completion date are as reported. No affected-person count is given because this desk has not seen one it can attribute to the company. The underlying campaign is filed at 25-0217. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. Hertz confirms data breach following Cl0p ransomware leaksCyberInsider
  2. Hertz confirms data breach tied to Cleo exploit, says customers’ personal data stolenComputing
  3. Cleo attack victim list grows as Hertz confirms customer data stolenIT Pro
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary