By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Hertz warns UK customers of Cleo-linked data breach | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Hertz warns UK customers of Cleo-linked data breach | Computer Weekly
News

Hertz warns UK customers of Cleo-linked data breach | Computer Weekly

News Room
Last updated: 2025/04/16 at 5:06 AM
News Room Published 16 April 2025
Share
SHARE

Car hire giant Hertz has disclosed a worldwide data breach affecting the UK and other major markets, after becoming embroiled in a serious compromise of Cleo Communications’ suite of managed file transfer (MFT) products by the Clop (aka Cl0p) ransomware gang.

Although parent Hertz Corporation – which besides the eponymous rental firm operates the Dollar and Thrifty brands – was earlier named by Clop on its leak site, the organisation had previously said there was no evidence of an intrusion.

In its latest notice, it did not name Clop or officially disclose an extortion or ransomware attack, but revealed that it appeared the incident had affected the personal information of certain individuals.

A spokesperson said: “On 10 February 2025, we confirmed that Hertz data was acquired by an unauthorised third party that we understand exploited zero-day vulnerabilities within Cleo’s platform in October 2024 and December 2024. Hertz immediately began analysing the data to determine the scope of the event and to identify individuals whose personal information may have been impacted.

“We completed this data analysis on 2 April 2025, and concluded that the personal information involved in this event may include the following regarding UK individuals: name, contact information, date of birth, driver’s license information and payment card information.”

Hertz has reported the incident to law enforcement and is in the process of engaging relevant national regulators. It is also working with Kroll to provide two years of free identity monitoring services to potentially affected individuals. This offer is also being made available to affected customers in the US – where other data including social security numbers, as well as Medicare and Medicaid identification, has also been affected.

Customers in Australia, Canada, the European Union (EU) and New Zealand can also consult localised notices for further guidance.

US-based Cleo has become the latest in a long line of file transfer services and tools to have been targeted by Clop – probably the most notable of these being the compromise of Progress Software’s MOVEit tool in the spring of 2023.

Its Cleo attacks arose through two common vulnerabilities and exposures (CVEs) tracked as CVE-2024-50623 and CVE-2024-55956 in its Harmony, VLTrader and LexiCom products.

The first of these arises through improper handling of file uploads in the Autorun directory, which enables an attacker to upload malicious files to a server and execute them. The second enables remote code execution (RCE) through Autorun by enabling an unauthenticated user to import and execute arbitrary Bash or PowerShell commands on the host using default settings. It also lets an attacker deploy modular Java backdoors to steal data and conduct lateral movement.

Dray Agha, senior manager of security operations at Huntress, which has been at the forefront of tracking the Cleo incident since the vulnerabilities first surfaced, said: “The Hertz data breach underscores the significant risks posed by unpatched zero-day vulnerabilities in widely used third-party platforms like Cleo. This highlights the importance of maintaining robust vulnerability management programmes to identify and address security gaps in software promptly, especially those used for sensitive data transfer.

“The breach also reflects a growing trend of cyber criminals targeting secure file transfer platforms, which are integral to many organisations’ operations. The evolving tactics of ransomware groups shift focus from encryption to data theft and extortion, signal the need for comprehensive cyber security strategies, including encryption of sensitive data at rest and in transit, and heightened monitoring of external connections.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Opera Mini rollout AI-powered mobile browser upgrade
Next Article Teens arrested with 5,000 smuggled ants as Kenya warns of changing trafficking trends
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

SpyraGravity is the ultimate weapon for your next water fight | Stuff
Gadget
Integrated infrastructure powers Nutanix and Pure Storage – News
News
Mom dies in tragic accident in front of kids as boy, 4, left fighting for life
News
Mukuru customers face balance errors after technical glitch
Computing

You Might also Like

News

Integrated infrastructure powers Nutanix and Pure Storage – News

5 Min Read
News

Mom dies in tragic accident in front of kids as boy, 4, left fighting for life

7 Min Read
News

Five free phone games you’ll actually play for hours – forget your PS5 and Xbox

10 Min Read
News

Yearly MariaDB LTS Release Integrates Vector Search

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?