Avis alerts nearly 300k car renters that crooks stole their info

Avis Rent A Car System has alerted 299,006 customers across multiple US states that their personal information was stolen in an August data breach.

The digital break-in occurred between August 3 and August 6, according to the car rental giant in filings with the Maine and California attorneys general.

On August 14, Avis determined that sensitive info had been “obtained by the unauthorized third party,” although the sample breach notification letter redacted the specifics, so we can’t say for sure what personal details were stolen.

Avis also cites “insider wrongdoing” under the breach disclosure section in the Maine filing, but doesn’t provide additional details about what happened.

“Since the incident occurred, we have worked with cybersecurity experts to develop a plan to enhance security protections for the impacted business application,” the letter sent to affected consumers says [PDF].

“In addition, we have taken steps to deploy and implement additional safeguards onto our systems, and are actively reviewing our security monitoring and controls to enhance and fortify the same,” it continues. 

The car rental company did not immediately respond to The Register‘s questions about the breach and what specific customer info was accessed. We will update this story if and when we hear back from Avis.

According to San Francisco-based law firm Schubert Jonckheer & Kolbe, this information may include customers’ names, addresses, dates of birth, driver’s license numbers, and financial information (including account numbers and credit or debit card numbers).

In addition to indicating that the crooks did make off with people’s credit card info, this also signals that a class-action lawsuit against Avis may soon be filed.

The rental company suggests that customers “remain vigilant against threats of identity theft or fraud,” and is offering affected individuals a free, one-year membership to Equifax credit monitoring services. The deadline to apply for this is December 31. ®

READ MORE HERE