Mashable 04月16日 01:13
Hertz customer data stolen in breach, possibly including licenses, social security numbers
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

赫兹租车公司近期遭遇大规模数据泄露,客户的个人信息可能被暴露。此次泄露事件影响广泛,涉及姓名、联系方式、出生日期、信用卡信息、驾照信息等。黑客利用了赫兹供应商Cleo的平台漏洞,在2024年10月和12月窃取了数据。虽然赫兹表示未发现数据被滥用,但仍建议客户保持警惕,并提供身份监控服务。此次事件波及范围广泛,包括美国、澳大利亚、加拿大、新西兰和英国等国家和地区,受影响的客户数量可能远超3409人。

🚨 赫兹租车公司发生大规模数据泄露事件,涉及客户的个人信息,包括姓名、联系方式、出生日期、信用卡信息等。

📅 数据泄露发生的时间是2024年10月和12月,黑客利用了赫兹供应商Cleo的文件共享平台的漏洞。

🌍 受影响的客户遍布多个国家和地区,包括美国、澳大利亚、加拿大、新西兰和英国等,仅在缅因州就有3409名客户受到影响。

🛡️ 赫兹表示未发现数据被滥用,但建议客户保持警惕,并提供两年的身份监控服务,以保护客户的个人信息安全。

This week car rental company Hertz notified its users of a wide-ranging data breach that exposed some customers' personal information.

On Monday, April 14, TechCrunch reported the appearance of a Notice of Data Incident on the Hertz website. According to the notice, personal information including names, contact information, date of birth, credit card information, driver's license information, and "information related to workers' compensation claims" were potentially exposed in the data breach.

Additionally, Social Security numbers, government IDs, passport information, Medicare or Medicaid IDs, and medical information from car accident claims may also have been stolen from "a very small number of individuals," said the notice.

Hertz discovered the breach on February 10, and customer data was stolen in October 2024 and December 2024.

Hertz did not say how many customers had their personal information exposed. However, according to a copy of the notice issued to Maine residents (published by the Office of the Maine Attorney General), the breach affected 3,409 customers in Maine alone. That means the true number of impacted individuals is likely far larger, especially considering that notices were also issued to customers in Australia, Canada, New Zealand, the United Kingdom, and beyond.

The breach came from a Hertz vendor called Cleo, which manages file-sharing platforms for the company. "On February 10, 2025, we confirmed that Hertz data was acquired by an unauthorized third party that we understand exploited zero-day vulnerabilities within Cleo’s platform in October 2024 and December 2024," read the notice. Hertz didn't provide any further specifics about the hack or hackers, but during those same months, cybersecurity firm Huntress reported "evidence of threat actors exploiting this [Cleo software]." Around that same time, ransomware group Clop claimed responsibility for data theft attacks targeting Cleo's servers.

In the notice, Hertz said it was "not aware of any misuse of personal information for fraudulent purposes in connection with the event." But it encouraged customers to "remain vigilant" of any instances of data breaches and shared resources on how to monitor account statements and credit reports, including how to place a fraud alert or credit freeze on their accounts. Some Hertz customers will also be offered "two years of identity monitoring services" free of charge.

Hertz did not immediately respond to a request for comment on this developing story, but we will update this article if we receive a response.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

赫兹租车 数据泄露 个人信息 网络安全
相关文章