Free tools Windows power users keep installed
One-click scans. No signup required.
Hertz confirmed a data incident involving its vendor Cleo Communications US, LLC. Attackers exploited zero-day vulnerabilities in Cleo file-transfer software during October and December 2024 and acquired data held in that environment. Security researchers and threat-intelligence reporting linked the wider Cleo campaign to CL0P (also called Cl0p or Clop), but Hertz described the actor only as an “unauthorized third party.” The available evidence describes data theft and extortion—not confirmed encryption of Hertz’s corporate network.
What happened in the Hertz breach?
Hertz used Cleo’s file-transfer platform for limited business purposes. The affected products—Cleo Harmony, VLTrader and LexiCom—were targeted through vulnerabilities later tracked as CVE-2024-50623 and CVE-2024-55956.
Hertz says data passing through the vendor environment was acquired by an unauthorized third party. Its public notice does not say that an attacker moved from Cleo into Hertz’s own corporate network, identify the exact files taken, or provide a worldwide number of affected people.
The event affected data associated with the Hertz, Dollar and Thrifty brands, but the notice says only certain individuals may have been impacted. Renting from one of those brands does not by itself establish that your information was involved.
Recommended Free Tools
#1 Best Overall
- Hardware encrypted drive
- Simple to use pin access. RPM-5400
- Administrator password feature
- Bus powered
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
Timeline
| Date | What is documented |
|---|---|
| October 2024 | Hertz identified a period when its data may have been acquired during exploitation of Cleo vulnerabilities. |
| December 2024 | A further exploitation period was identified. |
| February 10, 2025 | Hertz confirmed that an unauthorized third party had acquired Hertz data. |
| April 2, 2025 | Hertz completed its analysis of potentially affected information. |
| April 2025 | Notifications began for potentially affected people in the United States and other jurisdictions. |
| April 15, 2025 | Hertz’s later SEC disclosure identified the first reported related class-action complaint. |
Sources: Hertz incident notice and Hertz SEC filing.
Why is CL0P being mentioned?
Security researchers connected the broader Cleo exploitation campaign to CL0P, a threat group also known as Cl0p or Clop and associated in threat-intelligence reporting with FIN11. Cl0p reportedly claimed responsibility for the Cleo data-theft attacks. Broadcom’s advisory and reporting from BleepingComputer describe the campaign and its exploitation of Cleo products:
- Broadcom security bulletin
- BleepingComputer report on Cl0p’s claim
- Mandiant/Google Cloud attribution commentary
That attribution should not be overstated. Hertz did not identify CL0P by name, and no public Hertz statement establishes that CL0P specifically accessed the Hertz data. The defensible description is that Hertz suffered a Cleo vendor compromise and that researchers linked the wider campaign to CL0P.
Rank #2
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
- Super fast USB 3.0 Connection - Data transfer speeds up to 10X faster than USB 2.0
- Software Free Design - With no admin rights needed
- Sealed from Physical Attacks by Tough Epoxy Coating
- Brute Force Self Destruct Feature
Was this a ransomware attack?
“Ransomware” can imply that an organization’s systems were encrypted. The available reporting instead centers on unauthorized access, data exfiltration and possible extortion through the Cleo platform. Mandiant said it had observed backdoors and data theft in Cleo cases but had not observed ransomware deployment in its cases at the time of its commentary.
There is no public confirmation that Hertz’s network was encrypted, that Hertz paid a ransom, or that ransomware operated inside Hertz’s environment. Calling this a CL0P-linked vendor data-theft campaign is more precise than saying CL0P encrypted Hertz.
What information may have been exposed?
Hertz’s U.S. notice uses “may include,” because the categories varied by person. Potentially affected information included:
Rank #3
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
| Category | Examples in the U.S. notice |
|---|---|
| Basic and contact data | Name, contact information and date of birth |
| Payment and driving data | Credit-card information and driver’s-license information |
| Claims information | Workers’ compensation claim information and injury-related information connected with vehicle-accident claims |
| Identity documents | Passport information |
| Government identifiers | Social Security or other government identification numbers for a very small number of individuals; Medicare or Medicaid numbers associated with workers’ compensation claims |
European and U.K. notices list overlapping but not identical categories, including names, contact details, dates of birth, driver’s-license data and payment-card information. Passport information was identified for a very small number of people in those notices. See the EU notice and U.K. notice.
How many people were affected?
Hertz’s public notices do not provide a definitive global total. A Washington attorney-general filing reports approximately 19,297 Washington residents as potentially affected. That is a state-specific figure and cannot be extrapolated to the United States or worldwide population. The filing is available at Washington’s breach document.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →What were the Cleo vulnerabilities?
Security advisories describe unauthenticated file-upload or download paths, command injection and remote-code-execution possibilities, depending on the vulnerability and product version. The affected product family included Harmony, VLTrader and LexiCom. Technical background is available from the Canadian Centre for Cyber Security and Huntress.
Rank #4
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
For the 2024 incident, Huntress reported that Cleo’s initial fix for CVE-2024-50623 did not fully stop exploitation and that version 5.8.0.21 remained vulnerable. Later advisories identified version 5.8.0.24 as the relevant fixed version for the December vulnerability. Those are historical incident details, not a substitute for checking Cleo’s current advisories before making software decisions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What Hertz has done
- Investigated the incident and worked with Cleo to address the vulnerabilities.
- Reported the event to law enforcement and relevant regulators.
- Analyzed potentially affected information and began notifications in April 2025.
- Arranged two years of dark-web monitoring through Kroll at no cost for potentially impacted individuals.
Hertz said it was not aware of fraudulent misuse connected with the incident when it issued its notice. That statement reflects knowledge at that time; it is not a guarantee that misuse can never occur.
What potentially affected people should do
- Read your individualized Hertz notice. It should indicate whether you are included and which information categories may apply.
- Use the Kroll offer through the instructions in that notice. Do not rely on an unsolicited email or an independently guessed enrollment link.
- Consider a fraud alert or credit freeze. A freeze is especially important if your notice identifies Social Security information, payment data or identity documents.
- Review financial accounts. Check bank and card statements and report unfamiliar transactions to the institution immediately.
- Replace compromised cards or documents when advised. Follow your bank, card issuer or government agency’s replacement process.
- Expect phishing. Treat messages impersonating Hertz, Kroll, a credit bureau, a bank or a law firm as suspicious. Navigate to official sites yourself rather than clicking unexpected links.
- Keep your records. Save the notice and correspondence in case you need to dispute an account, document identity theft or respond to later legal or tax issues.
What remains unknown
- Hertz has not published a worldwide affected-person total in the cited notices.
- The exact files and individuals involved have not been publicly itemized.
- There is no public Hertz confirmation that its corporate network was encrypted or that it paid a ransom.
- CL0P attribution applies to the broader Cleo campaign in researcher reporting, not to a publicly proven CL0P intrusion into Hertz systems.
Litigation is not a finding of liability
Hertz disclosed multiple proposed class actions after the incident. Its SEC filing says the complaints generally sought injunctive relief and unspecified damages, with ten similar complaints following the first reported filing. A complaint contains allegations; it does not establish negligence, damages, liability or a settlement. The filing is at the SEC.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteThe broader security lesson
A managed file-transfer service can become a high-impact concentration point even when it is used for limited purposes. Organizations reduce that risk by validating patches rather than assuming the first fix worked, segmenting transfer systems, minimizing the sensitive data sent through vendors, retaining usable logs and monitoring third-party exposure. For customers, the practical distinction is equally important: a vendor data compromise can expose personal information without being a conventional ransomware infection of the company’s endpoints.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




