Latest / Tech Talks With Kinsoft / Hertz 2025 Data breach
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. This is where
- 0:02we unpack the stories shaping our digital world
- 0:04and hopefully help you navigate the tricky bits
- 0:06of tech and security. Today, we're looking at
- 0:09a really critical cybersecurity incident, one
- 0:12that goes way beyond just a single company, actually.
- 0:15It's the recent Hertz data breach. And unfortunately,
- 0:19it's hit customers right here in Australia, too.
- 0:22Yeah. And our goal today isn't just to rehash
- 0:24the headlines. We want to get into not just what
- 0:27happened, but really why it matters, particularly
- 0:29this whole area of third party vendor security,
- 0:33which often flies under the radar. This whole
- 0:35event, it's definitely concerning, but it's also
- 0:37a serious wake up call, you know, for people,
- 0:40for businesses. It shows just how connected everything
- 0:42is and maybe more vulnerable than we think. Absolutely.
- 0:45And what I find really interesting here is how
- 0:47a huge company like Hertz, you'd assume they
- 0:49have pretty solid security, right? But they got
- 0:52compromised, not through their own front door,
- 0:54so to speak, but through a weakness in a vendor
- 0:57they were using for apparently limited purposes.
- 0:59It's like locking your house, but forgetting
- 1:01the side gate used by the gardener. That's a
- 1:03great analogy. OK, let's unpack this properly
- 1:05then. So the basics first. Hertz has started
- 1:08telling customers their data was involved. And
- 1:10Hertz Australia specifically confirmed, yes.
- 1:13Australians are affected. So this isn't just
- 1:15some overseas story. It's local. Right. And the
- 1:18way it happened is, well, it's a classic supply
- 1:21chain attack, really. It wasn't Hertz's own systems
- 1:23that failed. It came from an incident at a third
- 1:26party, a company called Clio. They provide a
- 1:29file sharing platform that Hertz used, the attackers,
- 1:33the Klopp cyber extortion group. They basically
- 1:35found and used what we call zero day vulnerabilities.
- 1:40Okay, zero -day vulnerabilities. That sounds
- 1:42pretty bad. Can you quickly break that down?
- 1:45What does zero -day actually mean? Sure. Think
- 1:47of it like finding a secret flaw, a hidden weakness,
- 1:50in a piece of software that the makers, the vendor,
- 1:52don't even know about yet. So they have literally
- 1:55zero days to fix it before the bad guys find
- 1:58it and start using it. In this case, Klopp found
- 2:00these weak spots in Clio's system before Clio
- 2:02could patch them. That gave the attackers basically
- 2:05a free pass in. Specifically, we know they used
- 2:08two flaws identified as CVE -2024 -50623 and
- 2:13CVE -2024 -55956. CVEs. Right. Those are the
- 2:18standard ID codes for vulnerability. Exactly.
- 2:21Common vulnerabilities and exposures. And these
- 2:23weren't small bugs. They were serious enough
- 2:25to let attackers get around security. It looks
- 2:27like this happened in... sort of two waves, October
- 2:302024 and then again in December 2024. That timeline
- 2:34is quite something, especially the gap between
- 2:36things happening and people finding out. Hertz
- 2:39confirmed they knew data was taken on February
- 2:4010th, 2025. But the investigation to figure out
- 2:44who was affected wasn't done until April 2nd.
- 2:46And then they started telling customers on April
- 2:4711th. But what's really striking is you said
- 2:50Klopp exploited this back in December 2024. And
- 2:53Hertz was apparently listed on Klopp's Darknet
- 2:55site then, December 24th. That's right. Listed
- 2:58on the leak site then. And the data itself seems
- 3:00to have been published about a month later, January
- 3:0224th, 2025. Wow. So the criminals had the data,
- 3:07even released it way before customers got the
- 3:09official word. That lag is definitely something
- 3:12individuals worry about. And it's important to
- 3:14know this wasn't just the main Hertz brand. It
- 3:17also affected customers of Dollar and Thrifty,
- 3:19which are, you know. part of the Hertz group.
- 3:21Right. So if you've rented from any of those
- 3:23three, especially here in Australia, you need
- 3:25to pay attention. Definitely. So the big question
- 3:28for everyone listening, what data actually got
- 3:31out? For Australians, we're talking name, contact
- 3:33details, date of birth, driver's license info,
- 3:36and crucially, payment card information. Yeah,
- 3:39that's the core PII, personally identifiable
- 3:43information. Hertz did say only a very small
- 3:46number also had passport details exposed. But
- 3:48still, that's really sensitive stuff. Extremely.
- 3:51And just to show the scale for U .S. customers,
- 3:53it even included things like Social Security
- 3:55numbers and workers comp info. That's a massive
- 3:58haul of personal data. It really is. But what's
- 4:01fascinating, technically speaking, is what Hertz
- 4:04has stressed. Their own investigation found no
- 4:08sign that Hertz's internal network was breached.
- 4:11It purely came through that third party, through
- 4:13Clio, which just hammers home the point about
- 4:16vendor risk. You can have the best locks on your
- 4:19own doors, but if your supplier leaves their
- 4:21door open. Then you're exposed anyway. Yeah.
- 4:23So what's Hertz doing about it? Apart from notifying
- 4:25people, obviously. Well, they've confirmed Clio,
- 4:28the vendor, took steps to investigate and fix
- 4:30those vulnerabilities. That's step one. Hertz
- 4:33also reported it to law enforcement and they're
- 4:35notifying the relevant regulators, which they
- 4:37have to do. Standard procedure. And importantly
- 4:40for those affected, as a precaution, Hertz is
- 4:43offering two years of free identity monitoring
- 4:45via Kroll. Ah, Kroll. They're a well -known name
- 4:49in this space. What does that monitoring typically
- 4:51involve? Yeah, it generally includes a few key
- 4:54things. Credit monitoring, so you get alerts
- 4:56if someone tries to open credit in your name.
- 4:59Identity restoration assistance, which is huge.
- 5:02Yeah. If the worst happens, they help you clean
- 5:04up the mess. And dark web surveillance. Meaning
- 5:07they scan those dodgy marketplaces to see if
- 5:09your details pop up. Exactly. They look for your
- 5:11stolen info being sold or traded. Hertz says
- 5:15they're not aware of any misuse of the data so
- 5:17far, but they're still urging everyone to be
- 5:20vigilant. Which is always good advice anyway,
- 5:22right? These things can take time to surface.
- 5:25Absolutely. Fraudsters might sit on data for
- 5:27months or even years. So let's connect this to
- 5:29the bigger picture. You mentioned supply chain
- 5:31risks and third -party vendor vulnerabilities.
- 5:35This Hertz case seems like exhibit A for that.
- 5:38It really is. It perfectly shows how even a company
- 5:41with presumably strong internal security can
- 5:45get tripped up by a partner. It forces a rethink
- 5:48of security, doesn't it? Yeah. It's not just
- 5:50about your own perimeter anymore. It's about
- 5:52this whole ecosystem of trust. And the trust
- 5:54needs constant checking, I suppose. Continuous
- 5:57verification, yeah. Companies often underestimate
- 6:00just how wide the damage can spread from one
- 6:03single compromised vendor. Like you said, Hertz's
- 6:06own systems weren't the entry point. It was Clio's
- 6:09weakness that Klopp exploited. It's like those
- 6:12Russian nesting dolls, you know? Ah, yeah. You
- 6:14think you're dealing with one company? But they
- 6:16rely on another who relies on another, each one
- 6:19a potential weak link. So boiling it down, what
- 6:23does this mean for you listening, whether you're
- 6:25just trying to keep your own data safe or you
- 6:27run a business? What are the practical lessons
- 6:29here? Well, for businesses especially, this needs
- 6:32to trigger some real action. It's not just theoretical
- 6:35risk anymore. First off, you absolutely must
- 6:38vet third -party vendors properly. before you
- 6:41integrate them. And that's more than just ticking
- 6:43boxes on a form, right? Oh, much more. It's digging
- 6:45into their security culture, their actual technical
- 6:48controls, how they handle incidents, even their
- 6:50technical debt. You can't just take their word
- 6:54for it. Need proof. Maybe independent audits.
- 6:57That sounds like a lot of work, especially if
- 6:59you use many vendors. It is. But it's essential.
- 7:02Second. Get strong cybersecurity clauses into
- 7:05your contracts. Make security standards, data
- 7:07protection rules, and breach notification requirements
- 7:09legally binding. Third, the principle of least
- 7:13privilege. We heard Hertz used Clio for limited
- 7:16purposes, but even that was enough. Only give
- 7:19vendors access to the absolute minimum data and
- 7:21systems they need to do their job. Nothing more.
- 7:24Seems obvious, but... I guess easy to let slip.
- 7:27Very easy. Convenience often wins over strict
- 7:29permissions. Or old access just doesn't get revoked
- 7:32when it's no longer needed. That's a ticking
- 7:34time bomb. Fourth, you have to monitor and audit
- 7:37what your third parties are doing. Continuously.
- 7:39Don't just set it up and forget about it. Regular
- 7:41checks, maybe pen testing your vendors if they're
- 7:44critical. Okay. Fifth batch, patch promptly.
- 7:46Obvious. But Clio's unpatched zero days were
- 7:49the way in here. That applies to everyone. Internal
- 7:51systems, vendor systems, everything. And finally,
- 7:54have an incident response plan that specifically
- 7:56thinks about third -party breaches. What happens
- 7:59if your vendor gets hit? How do you find out?
- 8:01How do you tell your customers? How do you make
- 8:02sure the vendor actually fixes it? Yeah, that's
- 8:05a scenario many probably haven't fully planned
- 8:07for. And thinking about Australian businesses,
- 8:09we're just as interconnected, aren't we? Relying
- 8:12on cloud services, SaaS platforms, the works.
- 8:16A breach in one supplier. Can cascade. Exactly.
- 8:19It can ripple right through the supply chain.
- 8:21That's why understanding cases like Hertz is
- 8:24vital. It's not just a big company problem. Any
- 8:27business, any size using external services. Faces
- 8:30this risk. So maybe the thinking, oh, we're too
- 8:32small or we only use reputable providers isn't
- 8:36quite enough. It's not. Because even those reputable
- 8:38providers might have their own vulnerabilities
- 8:40or their suppliers might. This raises that crucial
- 8:43question. How do you secure your entire digital
- 8:46world, not just your own little corner? The core
- 8:49message really is that security is shared. Everyone
- 8:52has a part to play. You need to secure every
- 8:54endpoint, every connection, internal systems,
- 8:56partner platforms, all of it. It's a constant
- 8:58effort. It's ongoing. Yeah. but totally necessary
- 9:01to protect trust, data, and ultimately your reputation.
- 9:05So the key takeaway from the Hertz breach. In
- 9:08this connected age, your security is really only
- 9:11as good as the weakest link in your digital supply
- 9:13chain. And often, as we saw here, that link is
- 9:16a third -party vendor. It's a serious reminder
- 9:19to look beyond your own walls. Definitely. And
- 9:22maybe a final thought for everyone listening.
- 9:23Just pause and think about all the apps and services
- 9:26you use daily. Your bank, streaming, shopping?
- 9:29How many different companies are actually involved
- 9:32in handling your data behind the curtain? And
- 9:34how would you even begin to check if those unseen
- 9:37partners are secure? It's tricky, but something
- 9:40we all need to be more aware of when we think
- 9:42about our own data safety. That's a really important
- 9:44point to ponder. And look, if today's discussion
- 9:47has got you thinking about your own business's
- 9:49security, or if you need some expert help navigating
- 9:52IT and cybersecurity, we do encourage you to
- 9:54check out www .kinsoft .com .au. The team there
- 9:58can help you talk through your specific needs,
- 10:00look at your risks, and make sure your digital
- 10:02setup is as strong and resilient as possible.
- 10:05Thank you so much for joining us on Tech Talks
- 10:07with Kinsoft today. We'll be back next time to
- 10:09unpack more of the stories shaping our tech world.