- A data breach at Avis exposes sensitive info of 300,000 customers.
- Avis responds with credit monitoring, but extra precautions like fraud alerts are advised.
In yet another high-profile data breach, Avis, the global car rental company, has revealed that hackers have exposed the personal information of roughly 300,000 individuals. The breach was found on August 5, 2024, and involved unauthorised access to one of the company’s commercial applications. The incident contributes to the growing number of cyberattacks on major organisations.
Avis moved quickly to resolve the incident. When the company discovered the unauthorised access, it promptly blocked access to the compromised application, conducted an investigation with the assistance of cybersecurity specialists, and alerted the right authorities including law enforcement.
According to a report filed with the Maine Attorney General’s Office, 299,006 customers were affected. The stolen data includes personal information such as names, mailing addresses, email addresses, phone numbers, dates of birth, credit card numbers with expiration dates and driver’s licence numbers – critical information that can be used for identity theft or fraud.
Avis’s response to the breach
Avis notified affected consumers that it has collaborated with cybersecurity specialists to plan to secure vulnerable systems. “We have developed a plan to enhance security protections for the impacted business application and are deploying additional safeguards across our systems. We are also reviewing and fortifying our security monitoring and controls to prevent similar incidents in the future,” the company stated.
The company confirmed that the unauthorised access occurred between August 3 and August 6, 2024, and that its investigation concluded in mid-August. While Avis responded swiftly, affected customers remain concerned about the long-term consequences of the stolen data.
What Avis is offering affected customers
To mitigate possible damage, Avis is providing all affected users with one year of free credit monitoring through Equifax. The service helps detect identity theft and resolving any concerns that may develop. While this feature provides some peace of mind, users are made aware that credit monitoring alone cannot prevent fraud; it only alerts the user after suspicious behaviour occurs.

What you should do
The company has advised its past and present customers to take precautions to protect themselves by carefully monitoring credit and financial statements for unauthorised activity. Even small, seemingly unimportant charges can be indicative of fraud.
Avis also suggests adding a fraud alert or security freeze on customers’ credit reports. A fraud alert requires creditors to make further efforts to verify an identity before giving new credit. In contrast, a security freeze restricts access to credit records, prohibiting anyone from creating new accounts without consent.
How to protect yourself
To place a fraud alert or security freeze, customers should contact one of the three major credit bureaus: Equifax, Experian, or TransUnion. Fraud alerts are free and notify financial businesses that an individual’s information may have been compromised, prompting credit vendors to verify an applicant’s identity. Contrarily, security freezes offer absolute protection by preventing the sharing of anyone’s credit report with creditors unless explicit consent has been given. However, the drawback of security freezes is that each affected individual must grant such permission each time they apply for new credit, a loan, or any other financial service.
This breach serves as further evidence that information can be exposed at any time. Since no system is completely safe, companies must take all necessary precautions to ensure that their customers’ data is kept secure. In turn, consumers should monitor their accounts and activate fraud alerts or security freezes to avoid identity theft.
Key lessons from the Avis data breach
This breach is, unfortunately, proof of something that is not new but rather expected. Even large companies like Avis are not immune to the threat posed by criminals, as evidenced by the numerous attacks organisations have experienced.
What is particularly horrifying about this breach is the type of data that was compromised. Many companies have suffered from similar incidents, and many threat actors have acquired customer databases before. However, when such sensitive data as credit card information or driver’s licences fall into the wrong hands, potential problems can follow individuals for the rest of their lives. Even though Avis provides its customers with up to one year of credit monitoring, this type of service only alerts the customers after their accounts have been compromised.
It’s crucial to take steps to ensure that the databases of large companies are secured from unauthorised access in the first place. Preventative measures are vital if we want to avoid compromises like this with our own accounts, especially as incidents like these become increasingly common.
Want to learn more about cloud and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is co-located with other leading events including Intelligent Automation Conference, BlockX, Digital Transformation Week, and Cyber Security & Cloud Expo.
Explore other upcoming enterprise technology events and webinars powered by TechForge here.
Author
View all postsAs a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.