If you received a The Hertz Corporation, including the Hertz Dollar and Thrifty Brands data breach notification letter, you may be entitled to financial compensation through a class action lawsuit — at no cost to you.
According to the Delaware Attorney General filing, the following types of personal information were compromised in the The Hertz Corporation, including the Hertz Dollar and Thrifty Brands data breach:
Each type of exposed data strengthens your legal claim. Courts have consistently recognized that the unauthorized disclosure of this information constitutes actionable harm.
The Hertz Corporation, along with its prominent subsidiary brands Dollar and Thrifty, stands as a global leader in the vehicle rental and transportation services industry. Operating millions of rental transactions annually across airports, neighborhood locations, and international hubs, the enterprise collects a vast repository of deeply sensitive consumer and corporate data. To facilitate seamless bookings, loyalty memberships, payment processing, and regulatory compliance, the corporation routinely gathers detailed personal identifying information, financial records, government identification documents, and travel itineraries for millions of customers worldwide.
In 2025, official disclosures submitted to the Delaware Attorney General revealed that The Hertz Corporation suffered a significant cybersecurity incident, compromising its network infrastructure and exposing sensitive consumer records. While large-scale retail and transportation network breaches typically involve sophisticated external intrusions, ransomware deployment, or third-party vendor compromises, incidents of this magnitude often stem from vulnerabilities in customer relationship management platforms, centralized reservation databases, or cloud-hosted payment processing gateways. Unauthorized actors frequently target these environments to exploit legacy systems or bypass perimeter defenses, gaining prolonged access to consumer databases before detection occurs.
The exposure resulting from this breach places affected individuals at severe, immediate risk of identity theft, financial fraud, and targeted phishing campaigns. Because modern rental car transactions require comprehensive verification, the compromised data categories likely include full names, home addresses, dates of birth, driver license numbers, passport details, credit and debit card numbers, and secure account credentials. Driver license and passport information cannot be easily changed like a password, leaving victims permanently vulnerable to synthetic identity fraud, fraudulent credit applications, and unauthorized account takeovers that can impact personal credit scores and financial well-being for years.
As a commercial enterprise entrusted with high-value consumer data, The Hertz Corporation is legally obligated to implement robust administrative, technical, and physical safeguards under state consumer protection statutes, the Federal Trade Commission Act, and applicable state data breach notification laws. These regulations require businesses to maintain adequate encryption standards, conduct regular security audits, and promptly monitor access to customer databases. The occurrence of a data breach of this scale strongly indicates potential failures in adhering to these foundational cybersecurity standards, suggesting that existing security measures were inadequate to protect consumer privacy against foreseeable digital threats.
Receiving a data breach notification letter from The Hertz Corporation serves as formal legal acknowledgment that your confidential information was compromised due to corporate security shortcomings. Legally, the receipt of this notice establishes the foundation and standing required to participate in a class action lawsuit against the company, enabling affected consumers to seek accountability and financial compensation. Importantly, under modern legal standards, victims do not need to prove that they have already suffered actual financial loss or identity theft to pursue legal action; the increased risk of future harm is sufficient. Our firm evaluates these cases on a strict contingency fee basis, meaning you pay absolutely nothing out of pocket and owe no fees unless we successfully recover compensation on your behalf.
You do not need to prove you were financially harmed to qualify. Courts have recognized that the exposure of personal data itself constitutes actionable harm. You may qualify if any of the following apply:
You received a data breach notification letter from The Hertz Corporation, including the Hertz Dollar and Thrifty Brands
You were a customer, patient, employee, or client of The Hertz Corporation, including the Hertz Dollar and Thrifty Brands
Your personal information was stored in The Hertz Corporation, including the Hertz Dollar and Thrifty Brands's systems
Your financial account, credit card, or banking information was disclosed
Your login credentials or passwords were exposed
You reside in the United States (all 50 states eligible)
Companies that suffer a data breach are legally required to notify affected individuals by mail. If you received a notification letter from The Hertz Corporation, including the Hertz Dollar and Thrifty Brands, it means your personal information — such as your name, Social Security number, financial data, or health records — was exposed in this breach.
Receiving that letter gives you legal standing to pursue compensation. You do not need to prove financial harm to file a claim — courts have recognized that the exposure of personal data itself is a violation of your rights.
Take these steps immediately to protect yourself and preserve your right to compensation.
Your The Hertz Corporation, including the Hertz Dollar and Thrifty Brands data breach notification letter is legal evidence. Store it in a safe place — physical and digital copies. It establishes that you were affected by this breach and strengthens your claim for compensation.
The Hertz Corporation, including the Hertz Dollar and Thrifty Brands is typically required to offer free credit monitoring to affected individuals. Check your notification letter for enrollment instructions and use all offered services — they help detect fraud early and document harm.
Contact Equifax, Experian, and TransUnion to place a free credit freeze. This prevents new accounts from being opened in your name and protects you from identity theft. You can lift the freeze at any time.
You have a limited window to file a claim. Contact our attorneys today for a free, no-obligation case review. We handle all The Hertz Corporation, including the Hertz Dollar and Thrifty Brands data breach cases on a contingency basis — you pay nothing unless we win.
Security Incident
Prior to AG notification
Unauthorized access to The Hertz Corporation, including the Hertz Dollar and Thrifty Brands's systems containing personal information.
Reported to Attorney General
April 11, 2025
The Hertz Corporation, including the Hertz Dollar and Thrifty Brands filed an official data breach notice with the Delaware AG.
Consumer Notification Letters Sent
Within weeks of AG filing
State law requires companies to mail notification letters to all affected individuals.
Legal Window — Act Now
Statute of limitations applies
State law sets a deadline to file claims. Waiting can forfeit your right to compensation.
Data breach victims may be entitled to several forms of compensation. The specific amounts depend on your state, the type of data exposed, and the company's conduct.
States like California allow $100–$750 per incident regardless of actual harm. Other states provide separate statutory remedies for data breach victims.
Reimbursement for any fraud charges, unauthorized transactions, or expenses you incurred as a direct result of the breach.
Compensation for hours spent monitoring accounts, disputing fraud, freezing credit, and dealing with the aftermath of the breach.
Reimbursement for the cost of credit monitoring services, identity theft protection, and related identity restoration expenses.
Exposure of financial account or credit/debit card information entitles victims to recover for actual and potential fraud losses.
Delaware's Computer Security Breach Prevention Act requires timely notification and imposes a duty to implement reasonable security procedures. Delaware residents may pursue civil action for companies that fail to protect their personal information.
These companies also reported data breaches to the Delaware Attorney General. If you received a letter from any of these organizations, you may also be entitled to compensation.
Supplemental: Loan Care, LLC. (Notice on Behalf of Atlantic Bay Mortgage, LLC.)
Delaware · Aug 2026
Supplemental to June 15, July 20, and August 25, 2023 notices: Harvard Pilgrim Healthcare (“Harvard Pilgrim”)
Delaware · Aug 2026
AT&T, Inc.
Delaware · Aug 2026
Supplemental: Loan Care, LLC. (Notice on Behalf of Atlantic Bay Mortgage, LLC.)
Delaware · Aug 2026
Supplemental to June 15, July 20, and August 25, 2023 notices: Harvard Pilgrim Healthcare (“Harvard Pilgrim”)
Delaware · Aug 2026
Supplemental: Loan Care, LLC. (Notice on Behalf of Atlantic Bay Mortgage, LLC.)
Delaware · Aug 2026
Contact us for a FREE consultation. No fee unless we win your case.
(786) 306-7278Free Claim ReviewLaw Office of David S. Harris