Hertz Customers Face Second Vendor Breach in 14 Months; Class Action Opens
Hertz customers face a second data breach in 14 months, with 153 million driver's license scans exposed via IDScan.net. This follows a 2024 breach at Cleo Communications, affecting tens of thousands. Hertz has not commented on the latest breach. A class action investigation is underway, and Caesars Entertainment, also listed as an IDScan.net client, denies current use.
How this was made

The 30-second read
Why it matters
The dual breaches could increase legal exposure and erode customer trust, affecting future bookings.
Market read
First report of a second breach for Hertz, raising litigation risk and sector‑wide data‑privacy concerns.
What to watch
Potential for insurance recoveries and the possibility that the breach does not materially affect revenue.
Background
Hertz previously disclosed a 2024 breach via Cleo Communications; the new IDScan.net breach adds a second exposure.
Ticker impact
Hertz is facing a second data breach involving a vendor (IDScan.net) that may trigger additional class-action litigation.
Downside pressure pending class-action outcomes.
New breach details are fresh and could lead to lawsuits, but the scale of financial impact is uncertain.
Market effects
Highlights data‑privacy risks for the car‑rental and broader consumer‑services sector.
U.S. market may see heightened scrutiny of third‑party vendor risk.
Sets a precedent for data‑breach liability across industries worldwide.
Counterpoint
Investors may view the breach as already priced in; focus on Hertz's operational recovery.
Key entities
- CompanyHertz Global Holdings
Car rental firm facing two data breaches.
- CompanyIDScan.net
Identity verification vendor implicated in the latest breach.
