October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Hertz Data Breach Linked to CL0P’s Cleo Vendor Attack: What Customers Need to Know

Hertz confirmed that attackers exploited Cleo file-transfer vulnerabilities in 2024 and acquired data associated with certain Hertz, Dollar and Thrifty individuals. Researchers linked the wider campaign to CL0P, but Hertz has not confirmed CL0P-specific access or encryption of its network.
From TheFinanceBase Team5 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Hertz confirmed a data incident involving its vendor Cleo Communications US, LLC. Attackers exploited zero-day vulnerabilities in Cleo file-transfer software during October and December 2024 and acquired data held in that environment. Security researchers and threat-intelligence reporting linked the wider Cleo campaign to CL0P (also called Cl0p or Clop), but Hertz described the actor only as an “unauthorized third party.” The available evidence describes data theft and extortion—not confirmed encryption of Hertz’s corporate network.

What happened in the Hertz breach?

Hertz used Cleo’s file-transfer platform for limited business purposes. The affected products—Cleo Harmony, VLTrader and LexiCom—were targeted through vulnerabilities later tracked as CVE-2024-50623 and CVE-2024-55956.

Hertz says data passing through the vendor environment was acquired by an unauthorized third party. Its public notice does not say that an attacker moved from Cleo into Hertz’s own corporate network, identify the exact files taken, or provide a worldwide number of affected people.

The event affected data associated with the Hertz, Dollar and Thrifty brands, but the notice says only certain individuals may have been impacted. Renting from one of those brands does not by itself establish that your information was involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-2000)
  • Hardware encrypted drive
  • Simple to use pin access. RPM-5400
  • Administrator password feature
  • Bus powered
  • Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm

Timeline

Date What is documented
October 2024 Hertz identified a period when its data may have been acquired during exploitation of Cleo vulnerabilities.
December 2024 A further exploitation period was identified.
February 10, 2025 Hertz confirmed that an unauthorized third party had acquired Hertz data.
April 2, 2025 Hertz completed its analysis of potentially affected information.
April 2025 Notifications began for potentially affected people in the United States and other jurisdictions.
April 15, 2025 Hertz’s later SEC disclosure identified the first reported related class-action complaint.

Sources: Hertz incident notice and Hertz SEC filing.

Why is CL0P being mentioned?

Security researchers connected the broader Cleo exploitation campaign to CL0P, a threat group also known as Cl0p or Clop and associated in threat-intelligence reporting with FIN11. Cl0p reportedly claimed responsibility for the Cleo data-theft attacks. Broadcom’s advisory and reporting from BleepingComputer describe the campaign and its exploitation of Cleo products:

That attribution should not be overstated. Hertz did not identify CL0P by name, and no public Hertz statement establishes that CL0P specifically accessed the Hertz data. The defensible description is that Hertz suffered a Cleo vendor compromise and that researchers linked the wider campaign to CL0P.

Rank #2
Apricorn 500GB Aegis Padlock USB 3.0 256-bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-500)
  • Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
  • Super fast USB 3.0 Connection - Data transfer speeds up to 10X faster than USB 2.0
  • Software Free Design - With no admin rights needed
  • Sealed from Physical Attacks by Tough Epoxy Coating
  • Brute Force Self Destruct Feature

Was this a ransomware attack?

“Ransomware” can imply that an organization’s systems were encrypted. The available reporting instead centers on unauthorized access, data exfiltration and possible extortion through the Cleo platform. Mandiant said it had observed backdoors and data theft in Cleo cases but had not observed ransomware deployment in its cases at the time of its commentary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is no public confirmation that Hertz’s network was encrypted, that Hertz paid a ransom, or that ransomware operated inside Hertz’s environment. Calling this a CL0P-linked vendor data-theft campaign is more precise than saying CL0P encrypted Hertz.

What information may have been exposed?

Hertz’s U.S. notice uses “may include,” because the categories varied by person. Potentially affected information included:

Rank #3
Sale
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty
Category Examples in the U.S. notice
Basic and contact data Name, contact information and date of birth
Payment and driving data Credit-card information and driver’s-license information
Claims information Workers’ compensation claim information and injury-related information connected with vehicle-accident claims
Identity documents Passport information
Government identifiers Social Security or other government identification numbers for a very small number of individuals; Medicare or Medicaid numbers associated with workers’ compensation claims

European and U.K. notices list overlapping but not identical categories, including names, contact details, dates of birth, driver’s-license data and payment-card information. Passport information was identified for a very small number of people in those notices. See the EU notice and U.K. notice.

How many people were affected?

Hertz’s public notices do not provide a definitive global total. A Washington attorney-general filing reports approximately 19,297 Washington residents as potentially affected. That is a state-specific figure and cannot be extrapolated to the United States or worldwide population. The filing is available at Washington’s breach document.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What were the Cleo vulnerabilities?

Security advisories describe unauthenticated file-upload or download paths, command injection and remote-code-execution possibilities, depending on the vulnerability and product version. The affected product family included Harmony, VLTrader and LexiCom. Technical background is available from the Canadian Centre for Cyber Security and Huntress.

Rank #4
Sale
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
  • Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

For the 2024 incident, Huntress reported that Cleo’s initial fix for CVE-2024-50623 did not fully stop exploitation and that version 5.8.0.21 remained vulnerable. Later advisories identified version 5.8.0.24 as the relevant fixed version for the December vulnerability. Those are historical incident details, not a substitute for checking Cleo’s current advisories before making software decisions.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What Hertz has done

  • Investigated the incident and worked with Cleo to address the vulnerabilities.
  • Reported the event to law enforcement and relevant regulators.
  • Analyzed potentially affected information and began notifications in April 2025.
  • Arranged two years of dark-web monitoring through Kroll at no cost for potentially impacted individuals.

Hertz said it was not aware of fraudulent misuse connected with the incident when it issued its notice. That statement reflects knowledge at that time; it is not a guarantee that misuse can never occur.

What potentially affected people should do

  1. Read your individualized Hertz notice. It should indicate whether you are included and which information categories may apply.
  2. Use the Kroll offer through the instructions in that notice. Do not rely on an unsolicited email or an independently guessed enrollment link.
  3. Consider a fraud alert or credit freeze. A freeze is especially important if your notice identifies Social Security information, payment data or identity documents.
  4. Review financial accounts. Check bank and card statements and report unfamiliar transactions to the institution immediately.
  5. Replace compromised cards or documents when advised. Follow your bank, card issuer or government agency’s replacement process.
  6. Expect phishing. Treat messages impersonating Hertz, Kroll, a credit bureau, a bank or a law firm as suspicious. Navigate to official sites yourself rather than clicking unexpected links.
  7. Keep your records. Save the notice and correspondence in case you need to dispute an account, document identity theft or respond to later legal or tax issues.

What remains unknown

  • Hertz has not published a worldwide affected-person total in the cited notices.
  • The exact files and individuals involved have not been publicly itemized.
  • There is no public Hertz confirmation that its corporate network was encrypted or that it paid a ransom.
  • CL0P attribution applies to the broader Cleo campaign in researcher reporting, not to a publicly proven CL0P intrusion into Hertz systems.

Litigation is not a finding of liability

Hertz disclosed multiple proposed class actions after the incident. Its SEC filing says the complaints generally sought injunctive relief and unspecified damages, with ten similar complaints following the first reported filing. A complaint contains allegations; it does not establish negligence, damages, liability or a settlement. The filing is at the SEC.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The broader security lesson

A managed file-transfer service can become a high-impact concentration point even when it is used for limited purposes. Organizations reduce that risk by validating patches rather than assuming the first fix worked, segmenting transfer systems, minimizing the sensitive data sent through vendors, retaining usable logs and monitoring third-party exposure. For customers, the practical distinction is equally important: a vendor data compromise can expose personal information without being a conventional ransomware infection of the company’s endpoints.

Quick Recap

Bestseller No. 1
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-2000)
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-2000)
Hardware encrypted drive; Simple to use pin access. RPM-5400; Administrator password feature
$339.82
Bestseller No. 2
Apricorn 500GB Aegis Padlock USB 3.0 256-bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-500)
Apricorn 500GB Aegis Padlock USB 3.0 256-bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-500)
Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm; Super fast USB 3.0 Connection - Data transfer speeds up to 10X faster than USB 2.0
$185.34
SaleBestseller No. 3
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$131.00
SaleBestseller No. 4
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$119.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.