Al Avis Car Rental Settles Class Action Over 2024 Data Breach Affecting 300,000 Customers
Article Content
- •Avis Car Rental experienced a significant data breach affecting 300,000 customers.
- •Customers can claim up to $5,000 for documented out-of-pocket losses due to the breach.
- •The settlement totals nearly $1 million, covering various costs including administration fees.
Avis Car Rental customers may receive compensation up to $5,000 following a data breach that occurred between August 3-6, 2024. The breach involved unauthorized access to personal information, including names, driver's license details, credit card numbers, birthdates, and phone numbers. Approximately 300,000 customers are affected, with claims being processed as part of a nearly $1 million settlement. Avis denies any wrongdoing but has agreed to compensate those impacted by the breach. Customers must submit claims by June 21, 2026, to qualify for reimbursement for out-of-pocket losses or to receive a pro rata cash payment. A final court hearing is scheduled for July 28, 2026, to approve the settlement. The breach has raised concerns about identity theft and financial fraud risks for affected individuals.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Avis in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…