TechCrunch News 04月15日 02:03
Hertz says customers’ personal data and driver’s licenses stolen in data breach
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

租车巨头赫兹(Hertz)近期通知客户,由于供应商遭受网络攻击,导致客户个人信息和驾照等数据泄露。此次数据泄露事件发生于2024年10月至12月期间,影响范围涉及多个国家和地区,包括澳大利亚、加拿大、欧盟、新西兰、英国以及美国部分州。泄露的数据种类繁多,涵盖客户姓名、出生日期、联系方式、驾照信息、支付卡信息以及工伤赔偿 claims 等。虽然赫兹表示受影响客户数量可能“远低于数百万”,但具体受影响人数尚未公布。此次事件源于赫兹的供应商 Cleo Software 遭受的网络攻击,该供应商曾于去年成为俄罗斯黑客团伙大规模黑客攻击的目标。

🚗 **事件概述:** 赫兹租车公司,包括其旗下 Dollar 和 Thrifty 品牌,已开始通知客户数据泄露事件,此次事件涉及客户个人信息和驾照等敏感数据。

🌍 **泄露范围:** 数据泄露事件影响范围广泛,涉及澳大利亚、加拿大、欧盟、新西兰、英国以及美国部分州,具体泄露数据类型因地区而异,但主要包括客户姓名、出生日期、联系方式、驾照信息和支付卡信息等。

💻 **事件原因:** 数据泄露源于赫兹的供应商 Cleo Software 遭受的网络攻击。黑客利用了 Cleo 软件中的零日漏洞,窃取了包括赫兹在内的多家公司的客户数据。

⚠️ **数据性质:** 泄露数据种类繁多,除了客户个人身份信息外,还包括支付卡信息和工伤赔偿 claims。此外,少数客户的社会安全号码和其他政府颁发的身份识别号码也被窃取。

Car rental giant Hertz has begun notifying its customers of a data breach that included their personal information and driver’s licenses.

The rental company, which also owns the Dollar and Thrifty brands, said in notices on its website that the breach relates to a cyberattack on one of its vendors between October 2024 and December 2024.

The stolen data varies by region, but largely includes Hertz customer names, dates of birth, contact information, driver’s licenses, payment card information, and workers’ compensation claims. Hertz said a smaller number of customers had their Social Security numbers taken in the breach, along with other government-issued identification numbers.

Notices on Hertz’s websites disclosed the breach to customers in Australia, Canada, the European Union, New Zealand, the United Kingdom

Hertz also disclosed the breach with several U.S. states, including California and Maine. Hertz said at least 3,400 customers in Maine were affected, but did not list the total number of affected individuals, which is likely to be significantly higher.

Emily Spencer, a spokesperson for Hertz, would not provide TechCrunch with a specific number of individuals affected by the breach but said it would be “inaccurate to say millions” of customers are affected.

The company attributed the breach to a vendor, Cleo Software, which last year was at the center of a mass-hacking campaign by a prolific Russia-linked ransomware gang.

Hertz is one of dozens of companies that used Cleo Software at the time of their data thefts. The Clop ransomware gang claimed last year to have exploited a zero-day vulnerability in Cleo’s widely used enterprise file transfer products, which allow companies to share large sets of sensitive data over the internet. By breaching these systems, the hackers stole reams of data from Cleo’s corporate customers.

Soon after, the Clop ransomware gang claimed on its dark web leak site that it stole data from close to 60 companies by exploiting the bug in their Cleo systems. In a later post, Clop claimed dozens more alleged corporate victims.

The data extortion campaign became one of the most notable mass-hacks of 2024.

At the time, Hertz, which was named on Clop’s site, said it had “no evidence” that Hertz data or Hertz systems were affected.

On Monday, Hertz’s spokesperson told TechCrunch it found no evidence that Hertz’s own network was affected by the breach, but confirmed that Hertz data “was acquired by an unauthorized third party that we understand exploited zero-day vulnerabilities within Cleo’s platform in October 2024 and December 2024.”

A Cleo executive did not respond to TechCrunch’s inquiry on Monday.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

赫兹租车 数据泄露 网络攻击 客户信息
相关文章