Hertz Data Breach: What Was Exposed and Where the Lawsuits Stand
Hackers did not break into Hertz. They broke into Cleo — the file-transfer software Hertz used to move data — and took customer records for Hertz, Dollar and Thrifty with them. Notification letters went out from April 2025. There is no settlement and no claim form; the lawsuits are still in their early stages. Here is the verified record and the three things worth doing now.
Revisado Editorialmente — Contenido revisado en cuanto a exactitud utilizando investigación legal publicada, datos gubernamentales y registros judiciales verificados. Vea nuestra metodología
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened and What Was Exposed
An unauthorised third party exploited zero-day vulnerabilities in Cleo, a managed file-transfer platform used by Hertz, with access occurring in October and December 2024. Hertz identified the incident on February 10, 2025, completed its assessment on April 2, 2025 and began notifying people from April 11, 2025.
The exposed data varies by person and is unusually broad: names, contact details, dates of birth, credit card information, driver's licence details and workers' compensation claim information. In a smaller number of cases it also included Social Security numbers, government IDs, passport information, Medicare or Medicaid IDs and injury-related vehicle accident data. The breach covers the Hertz, Dollar and Thrifty brands.
The lawsuits allege Hertz and Cleo failed to implement reasonable data security and that affected customers now face a lasting risk of identity theft.
Case Details
At least eleven proposed class actions were filed and transferred to the U.S. District Court for the Northern District of Illinois, Western Division (the first, Jiwani v. Cleo Communications U.S., LLC and Hertz, was filed April 15, 2025; related docket numbers include 3:25-cv-50178). Hertz has not published a total number of affected people; state attorney-general filings give partial figures — 96,665 in Texas, 34,452 in Massachusetts, 19,297 in Washington, 4,657 in New Hampshire, 3,409 in Maine, 1,822 in Montana and about 500 in California.
Status: Active Litigation — No Settlement, No Claim Form
A separate route is already open: several firms are running mass arbitration campaigns, in which hundreds or thousands of customers file individual arbitration claims rather than joining a class. That is a real legal step with real trade-offs — it typically means giving up the class action, and terms depend on the firm.
⚠️ Do not confuse this with the second Hertz incident: on June 29, 2025 Hertz suffered a network disruption and confirmed on July 3, 2025 that personal information may have been accessed. That is a different event with its own timeline — a letter about one says nothing about the other.
Who Is Affected — and What to Do Now
You are likely affected if you rented from Hertz, Dollar or Thrifty and received a notification letter from April 2025 onward. Because driver's licence numbers and, for some, Social Security numbers were involved, this breach sits at the higher-risk end.
Three things worth doing, in order:
• Freeze your credit at all three bureaus. It is free, takes minutes, and is the single most effective step when licence and SSN data are circulating.
• Take the credit monitoring offered in your letter if you have not — it costs nothing and enrolment windows close.
• Keep everything. The notification letter, any fraudulent charges with dates and amounts, hours spent resolving them, and any money you spent. Documented losses are what settlement claim forms pay best, and this one does not exist yet.
What a Settlement Could Eventually Look Like
Hertz Breach Timeline
- 1
October and December 2024 — The Cleo Intrusions
Attackers exploit zero-day flaws in the Cleo file-transfer platform and access Hertz customer data.
- 2
February 10, 2025 — Hertz Identifies the Incident
The company confirms its data was among what was taken from Cleo.
- 3
April 2, 2025 — Assessment Completed
Hertz finishes determining who and what was affected.
- 4
April 11, 2025 — Notification Letters
Notices go to affected customers and to state attorneys general; the first class action follows on April 15.
- 5
2025-2026 — Consolidation, No Settlement
Eleven-plus class actions land in the Northern District of Illinois; mass arbitration campaigns run in parallel. Nothing to claim yet.
Watch Out For
A breach with licence and card data attracts predators fast:
'Hertz settlement claim' sites
No settlement and no administrator exist. Any site collecting your rental history or ID details for a Hertz payout is harvesting data, not filing a claim.
Calls or emails 'from Hertz security'
The real response was a mailed notice plus a credit-monitoring code. Nobody legitimate will call asking you to confirm your card number, licence number or SSN because of this breach — that is the stolen data being used against you.
Confusing the two 2025 incidents
The Cleo breach (disclosed February-April 2025) and the June-July 2025 network incident are separate. Check the date on your letter before assuming which one applies to you.
Hertz Data Breach - FAQ
Can I file a claim for the Hertz data breach?
Not yet. The class actions are consolidated in Illinois federal court but no class has been certified and no settlement exists, so there is no claim form. The only active route today is mass arbitration through a law firm, which is a different path with different trade-offs.
What information was exposed?
Names, contact details, dates of birth, credit card information, driver's licence details and workers' compensation claim data; in a smaller number of cases Social Security numbers, government IDs, passport data, Medicare/Medicaid IDs and accident-related information. Your letter lists what applied to you.
How many people were affected?
Hertz has not published a total. State filings show at least 96,665 people in Texas, 34,452 in Massachusetts, 19,297 in Washington and smaller numbers elsewhere — the nationwide figure is certainly far higher, but no verified total exists.
Was it Hertz's systems that were hacked?
No. The intrusion was into Cleo, a third-party managed file-transfer platform Hertz used. That is why the lawsuits name both companies — the legal question is whether Hertz was reasonable in entrusting the data to that vendor and whether Cleo secured it properly.
I rented from Dollar or Thrifty — am I included?
Yes, those brands are part of the same corporate group and are covered by the same incident and the same litigation.
Should I take the free credit monitoring?
Yes — it costs nothing and accepting it does not waive any legal rights or prevent you from participating in a future settlement. Freezing your credit at all three bureaus is the stronger step, and you can do both.
How long will the lawsuits take?
Data-breach class actions of this size commonly take two to four years from filing to a settlement with a claim window, and longer if there are appeals. Filing began in April 2025. We update this page when the docket moves.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.