LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › The Hertz Corporation Data Breach Notice (Oregon Attorney General)

HIGH severityConfirmedHow we verify

The Hertz Corporation Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·April 11, 2025
The Hertz Corporation Data Breach Notice (Oregon Attorney General)

Occurred October 27, 2024 · publicly disclosed April 11, 2025. Approximately 1000175 people affected.

HIGH
Severity
1000175
People affected
1
Data types exposed
April 11, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Hertz Corporation disclosed a data breach on April 11, 2025, that exposed the personal information of 1,000,175 individuals; the breach occurred on October 27, 2024. Affected individuals should review the notice filed with the Oregon Attorney General and take recommended steps to protect their data.

Severity & verification
HIGH severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
1000175 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

More than one million people may have had personal information exposed in a data incident involving The Hertz Corporation. For customers and others whose details sit in rental and related records, the practical question is straightforward: whether information tied to their identity could be misused, and what they can do about it.

Public notice came through a filing with the Oregon Department of Justice. The company reported the matter on April 11, 2025, and placed the underlying incident on October 27, 2024. Exact technical details remain limited in the public record, but the scale of the notice—1,000,175 people—makes clear why ordinary customers should treat the event as relevant rather than abstract.

What happened

The Hertz Corporation notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on April 11, 2025. That filing states the incident itself occurred on October 27, 2024. The notice identifies personal information as having been exposed, consistent with the breach notification language used in the filing.

Public detail beyond those points is limited. The available record does not describe how systems were accessed, which systems were involved, how long unauthorized access lasted, or whether data was copied, viewed, or otherwise handled. No specific threat actor is named in the facts provided. Counts of affected people are given as 1,000,175 in the reported notice; other metrics such as file volumes or financial loss figures are not included in the disclosed summary.

How a breach like this happens

Incidents that lead to notices about personal information often follow familiar patterns, even when a particular case leaves method undisclosed. Attackers may obtain credentials through phishing or reused passwords, exploit unpatched software, or abuse misconfigured remote access. Once inside an environment that holds customer or employee records, they may move laterally, locate databases or file stores, and exfiltrate or encrypt data.

Organizations that process high volumes of identity and transaction data are frequent targets because the information can be resold or used in fraud. Detection can lag weeks or months, which is one reason a notice date can sit well after the stated incident date. None of this assigns a specific technique or group to the Hertz matter; it only describes how breaches of this general type typically unfold when full forensic detail is not public.

The Hertz Corporation and its sector

The Hertz Corporation is a major vehicle rental company serving consumers and business travelers across large markets. Firms in this sector routinely collect and retain information needed to verify identity, process payments, manage reservations, handle insurance and claims, and meet regulatory or contractual requirements. That can include names, contact details, driver’s license data, payment-related information, and other records tied to rentals and memberships.

A breach affecting a company of this profile is consequential because the same identity attributes used to rent a car are useful for impersonation, account takeover, and financial fraud elsewhere. Travel and mobility businesses also sit at the intersection of consumer data and operational systems, so disruptions or disclosures can affect both individual privacy and trust in everyday commercial services. The Oregon filing does not itself establish negligence; it records that a notice was made and that a large number of people were included in the affected population as reported.

What data was at risk

The breach notification, as reflected in the facts, names personal information as exposed. It does not itemize every field in the public summary provided here. For organizations like Hertz, personal information in ordinary operations often spans identifiers and contact data, and may extend to documents or attributes required for vehicle rental; however, the exact contents of what was involved in this incident remain confirmed only at the level of “personal information” in the notice language.

Readers should not assume a full catalog of data elements without further official detail. Where a notice stops at a broad category, the responsible approach is to treat identity-related exposure as possible and to monitor for misuse, rather than to invent a precise inventory.

The real-world impact

For affected individuals, the main risks are identity fraud, targeted phishing that references a known rental relationship, and attempts to open accounts or change existing ones using leaked personal details. Even when payment card numbers are not confirmed as part of a given notice, personal information alone can support social-engineering attacks. Monitoring credit reports, watching account statements, and treating unexpected messages that cite Hertz or rental activity with caution are concrete steps that reduce harm without requiring technical expertise.

For the organization, a large-scale notice can mean regulatory scrutiny, notification costs, customer support load, and reputational pressure. The filing date of April 11, 2025, and the incident date of October 27, 2024, illustrate a multi-month gap between event and public Oregon reporting, which is not unusual when investigations and legal notice processes run in parallel, but it leaves people with a delayed window in which to act. No dollar figures or findings of fault are stated in the facts given.

Were you affected?

If you have rented from Hertz, held a related account, or otherwise shared personal information with the company, treat the notice as a reason to verify your own exposure rather than to ignore it. Review any official correspondence you receive, place fraud alerts or credit freezes if appropriate in your jurisdiction, and change passwords on important accounts—especially if you reused credentials. Keep records of rental confirmations and watch for unexpected credit inquiries or account activity.

You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets. That check does not replace official notices from Hertz or regulators, but it can help you see whether your email is circulating in broader breach corpora and prioritize further monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyThe Hertz Corporation security record
74/100
DoxxScan™ · Moderate doxx risk
C 69Mixed record

1 reported incident on record.

See The Hertz Corporation’s full breach history →

More recent breaches

Decisely Insurance Services Data Breach Notice (Oregon Attorney General)December 30, 2025Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)December 29, 2025Apro, LLC d/ Data Breach Notice (Oregon Attorney General)December 29, 2025CareOregon Data Breach Notice (Oregon Attorney General)December 26, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the The Hertz Corporation Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram