The Hertz Corporation Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
The Hertz Corporation disclosed a data breach on April 11, 2025, that exposed the personal information of 1,000,175 individuals; the breach occurred on October 27, 2024. Affected individuals should review the notice filed with the Oregon Attorney General and take recommended steps to protect their data.
More than one million people may have had personal information exposed in a data incident involving The Hertz Corporation. For customers and others whose details sit in rental and related records, the practical question is straightforward: whether information tied to their identity could be misused, and what they can do about it.
Public notice came through a filing with the Oregon Department of Justice. The company reported the matter on April 11, 2025, and placed the underlying incident on October 27, 2024. Exact technical details remain limited in the public record, but the scale of the notice—1,000,175 people—makes clear why ordinary customers should treat the event as relevant rather than abstract.
What happened
The Hertz Corporation notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on April 11, 2025. That filing states the incident itself occurred on October 27, 2024. The notice identifies personal information as having been exposed, consistent with the breach notification language used in the filing.
Public detail beyond those points is limited. The available record does not describe how systems were accessed, which systems were involved, how long unauthorized access lasted, or whether data was copied, viewed, or otherwise handled. No specific threat actor is named in the facts provided. Counts of affected people are given as 1,000,175 in the reported notice; other metrics such as file volumes or financial loss figures are not included in the disclosed summary.
How a breach like this happens
Incidents that lead to notices about personal information often follow familiar patterns, even when a particular case leaves method undisclosed. Attackers may obtain credentials through phishing or reused passwords, exploit unpatched software, or abuse misconfigured remote access. Once inside an environment that holds customer or employee records, they may move laterally, locate databases or file stores, and exfiltrate or encrypt data.
Organizations that process high volumes of identity and transaction data are frequent targets because the information can be resold or used in fraud. Detection can lag weeks or months, which is one reason a notice date can sit well after the stated incident date. None of this assigns a specific technique or group to the Hertz matter; it only describes how breaches of this general type typically unfold when full forensic detail is not public.
The Hertz Corporation and its sector
The Hertz Corporation is a major vehicle rental company serving consumers and business travelers across large markets. Firms in this sector routinely collect and retain information needed to verify identity, process payments, manage reservations, handle insurance and claims, and meet regulatory or contractual requirements. That can include names, contact details, driver’s license data, payment-related information, and other records tied to rentals and memberships.
A breach affecting a company of this profile is consequential because the same identity attributes used to rent a car are useful for impersonation, account takeover, and financial fraud elsewhere. Travel and mobility businesses also sit at the intersection of consumer data and operational systems, so disruptions or disclosures can affect both individual privacy and trust in everyday commercial services. The Oregon filing does not itself establish negligence; it records that a notice was made and that a large number of people were included in the affected population as reported.
What data was at risk
The breach notification, as reflected in the facts, names personal information as exposed. It does not itemize every field in the public summary provided here. For organizations like Hertz, personal information in ordinary operations often spans identifiers and contact data, and may extend to documents or attributes required for vehicle rental; however, the exact contents of what was involved in this incident remain confirmed only at the level of “personal information” in the notice language.
Readers should not assume a full catalog of data elements without further official detail. Where a notice stops at a broad category, the responsible approach is to treat identity-related exposure as possible and to monitor for misuse, rather than to invent a precise inventory.
The real-world impact
For affected individuals, the main risks are identity fraud, targeted phishing that references a known rental relationship, and attempts to open accounts or change existing ones using leaked personal details. Even when payment card numbers are not confirmed as part of a given notice, personal information alone can support social-engineering attacks. Monitoring credit reports, watching account statements, and treating unexpected messages that cite Hertz or rental activity with caution are concrete steps that reduce harm without requiring technical expertise.
For the organization, a large-scale notice can mean regulatory scrutiny, notification costs, customer support load, and reputational pressure. The filing date of April 11, 2025, and the incident date of October 27, 2024, illustrate a multi-month gap between event and public Oregon reporting, which is not unusual when investigations and legal notice processes run in parallel, but it leaves people with a delayed window in which to act. No dollar figures or findings of fault are stated in the facts given.
Were you affected?
If you have rented from Hertz, held a related account, or otherwise shared personal information with the company, treat the notice as a reason to verify your own exposure rather than to ignore it. Review any official correspondence you receive, place fraud alerts or credit freezes if appropriate in your jurisdiction, and change passwords on important accounts—especially if you reused credentials. Keep records of rental confirmations and watch for unexpected credit inquiries or account activity.
You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets. That check does not replace official notices from Hertz or regulators, but it can help you see whether your email is circulating in broader breach corpora and prioritize further monitoring.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.