Skip to content
Back to Blog
low severity April 11, 2025 · 4 min read

The Hertz Corporation Data Breach Notice (Oregon Attorney General)

If you received a notice from The Hertz Corporation, here’s what the filing says was exposed, and what to do about it.

The Hertz Corporation notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on April 11, 2025. The filing puts the incident itself on October 27, 2024.

The Hertz Corporation Data Breach Notice (Oregon Attorney General)

The Hertz Corporation notified Oregon residents that a data breach affecting 1,000,175 people occurred on October 27, 2024. The company filed the notice with the Oregon Department of Justice on April 11, 2025 — 166 days later.

Personal information from 1,000,175 people is now outside Hertz’s control

If you received a letter from Hertz, your records were part of this incident. The filing lists personal information as exposed. No passwords, no financial account numbers, and no permanent government identifiers such as Social Security numbers were included in the categories disclosed. That is genuine good news. The data that was exposed cannot be changed like a password or canceled like a credit card, but the absence of the most dangerous identifiers sharply limits what thieves can do with it.

What the exposed personal information actually enables

Names, addresses, and driver’s license data remain valuable for identity thieves even years later. With this combination, someone can attempt to open new accounts in your name, file fraudulent tax returns, or impersonate you when dealing with government agencies or rental companies. Because Hertz is a major car rental business, the records almost certainly include details tied to past rentals, reservations, or loyalty accounts. This makes the information more useful for targeted fraud that looks legitimate — such as disputing a rental charge or requesting a duplicate receipt.

The 166-day gap between the October 27, 2024 incident and the April 11, 2025 filing is the most striking fact in the record. State law allows companies time to investigate and confirm the scope before notifying affected residents. Whether that window was used efficiently is not stated in the filing. What matters to you is that the information has had months to circulate before any public notice reached Oregon customers.

Why the lack of passwords and SSNs changes your risk level

Because no credentials were exposed, this breach does not put your Hertz account at direct risk of takeover. You do not need to change your Hertz password because of this incident. That instruction would waste your time and point you at the wrong threat.

The exposed driver’s license data is the most concerning element. A driver’s license number combined with name and address can be used to support synthetic identity applications or to bypass certain verification steps at other companies. However, without a Social Security number attached, many high-value identity theft pathways — such as opening credit cards or claiming large tax refunds — become significantly harder for fraudsters to complete.

How to determine whether this breach affects you

The Hertz Corporation is required to notify affected individuals directly, usually by mail. If you have not received a letter, your information was most likely not included. Anyone who has moved since October 27, 2024 should contact Hertz customer service to confirm whether their records were part of the 1,000,175 affected. Absence of a letter is usually a reliable signal, but last-known-address mailings can miss people.

The long-term reality of this type of exposure

Personal information of this kind does not expire. While the immediate risk of account takeover is low, the data can be sold and re-sold on criminal marketplaces for years. The most practical protection is vigilance rather than panic. Monitor your credit reports, watch for unexpected rental or loyalty activity, and treat any unsolicited contact claiming to be from Hertz with skepticism.

Because this filing reached the Oregon Attorney General, Oregon residents have specific rights under state law. You can request a copy of the incident details from the company and ask what exact fields applied to your record. The public filing names only the broad category “personal information,” so your individual notification letter is the only document that can tell you the precise details involved.

Practical steps that address this specific exposure

  • Place a free fraud alert with the three major credit bureaus. This forces lenders to verify your identity before opening new accounts and lasts for one year. It is the single most effective step for this type of breach.
  • Review your annual credit reports at AnnualCreditReport.com. Look for accounts or inquiries you do not recognize, especially anything involving vehicle rentals, loans, or retail credit.
  • Monitor your mail and email for unexpected Hertz communications or collection notices. Fraudsters sometimes use rental loyalty data to create convincing-looking disputes or refund requests.
  • Be cautious with any request for your driver’s license number. If someone contacts you claiming to be from Hertz or a partner company, call them back using a number from the official Hertz website rather than replying to the message.
  • Keep records of the breach notification letter. Should identity theft occur later, the letter serves as proof that your information was compromised in this incident and can help with disputes.

The scale — more than one million people — reflects Hertz’s large customer base rather than the technical severity of the breach itself. For those who were notified, the exposure is real but contained. No passwords were exposed, no Social Security numbers were listed, and the most dangerous permanent identifiers are absent from the record. Focus your attention on credit monitoring and fraud alerts. That is the part you still control.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed April 11, 2025
Last reviewed July 22, 2026
Affected 1000175
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email