HERTZ.COM Listed by clop Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
HERTZ.COM has been listed by the Clop ransomware group, with the incident reported on January 24, 2025. An undisclosed number of people may be affected by the exfiltration of internal files; individuals are advised to check for any personal impact and take appropriate security measures.
Ransomware groups continue to pressure large consumer-facing companies by claiming data theft and threatening public leaks, a pattern that has become a regular feature of the current cyber threat landscape. On January 24, 2025, the clop ransomware group listed HERTZ.COM among its claimed victims, asserting that internal files had been exfiltrated. The number of people affected remains unknown, and public detail on the scale and method of the incident is limited. For customers and partners of a major car-rental operator, any such claim raises immediate questions about what information may have left the company’s systems and what practical steps follow.
Because the listing itself is an unverified claim by the threat actor, the full picture of what occurred is not yet confirmed by independent reporting or by the organisation. What is known is confined to the group’s assertion of a ransomware attack involving the removal of internal files. That limited public record still warrants careful attention given the volume of personal and commercial data typically handled by a global rental brand.
What happened
According to the available record, HERTZ.COM was listed by the clop ransomware group on January 24, 2025. The group claims that internal files were exfiltrated in a ransomware attack. No figure has been published for the number of people affected, and the precise timing of any intrusion, the initial access method, and the volume of data taken have not been disclosed in the public facts. The listing constitutes a claim by the group rather than a confirmed admission by the company. Beyond the statement that internal files were removed, further technical or operational detail remains undisclosed.
Inside clop
Clop is a well-documented ransomware operation that has operated for several years under a double-extortion model: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if ransom demands are not met. The group has historically focused on large organisations across multiple sectors and has been linked to high-volume campaigns that exploit vulnerabilities in widely used file-transfer and remote-access software. Its public leak site is used to name alleged victims and, in some cases, to release samples of stolen material as proof. Clop’s operators are generally assessed by security researchers as Russian-speaking and financially motivated. None of these established patterns, however, constitute independent confirmation of the specific claims made about HERTZ.COM; the group’s listing of the company remains an unverified assertion.
About HERTZ.COM
Hertz.com is the primary online portal for The Hertz Corporation, a long-established car-rental company founded in 1918 and now operating as a subsidiary of Hertz Global Holdings. The business provides vehicle rentals—cars, trucks and utility vehicles—to individual consumers and corporate clients worldwide, along with related services such as car sales, vehicle leasing and fleet management. Customers use the website to book rentals, manage reservations and access promotions. As a major player in the mobility and travel sector, the organisation routinely processes booking details, identity information, payment data and corporate account records. A breach claim involving such a company is consequential because of the breadth of personal and commercial data that rental operators typically hold and the potential for that information to be misused if it has left controlled systems.
What was likely exposed
The public facts state only that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases or specific data categories has been disclosed. Organisations of this kind commonly maintain customer reservation records, contact details, driver’s-licence information, payment-card data, loyalty-programme profiles and internal corporate documents. Whether any of those categories were among the files claimed by clop is unconfirmed. The exact contents of the material the group says it took therefore remain unknown, and any assessment of exposure must treat the named data types as limited to the general description “internal files.”
What's at stake
For individuals, the principal risks centre on the possible misuse of personal information that may have been present in internal systems—identity fraud, targeted phishing, or unauthorised use of payment or reservation details. Because the number of affected people is unknown and the precise data set is unconfirmed, the actual scope of individual harm cannot yet be measured. For the organisation, the stakes include operational disruption, potential regulatory scrutiny under data-protection rules, reputational damage, and the costs of investigation and customer notification if the claim is substantiated. In the broader threat landscape, a listing by a group such as clop also signals that stolen material could later appear on criminal markets or be used in secondary attacks against customers and partners.
If your data was in this claimed breach
If you have used Hertz services, treat the listing as a prompt to review your accounts rather than as proof that your records were taken. Change passwords associated with any Hertz-related login, enable multi-factor authentication where available, and monitor bank and credit-card statements for unfamiliar charges. Consider placing a fraud alert with credit bureaus if you believe sensitive identity documents may have been involved. Keep records of any unusual communications that reference recent rentals. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets, providing an additional early-warning check while official details remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
RIDERTA.COM Listed by clop Ransomware GroupKIRBYCORP.COM Listed by clop Ransomware GroupPILOTTHOMAS.COM Listed by clop Ransomware GroupGTIMPORTS.NET Listed by clop Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the HERTZ.COM Listed by clop Ransomware Group →
Publicly posted by clop — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.