Avis Rent A Car System LLC, a subsidiary of Avis Budget Group, experienced a data breach that was disclosed on February 10, 2026. This incident stemmed from a ransomware attack detected on January 15, 2026, which impacted systems used for customer reservations and loyalty programs. The company officially confirmed the breach and began notifying affected individuals on February 20-25, 2026. State Attorneys General were also notified around February 10, 2026.
The breach may have involved personal information including names, addresses, phone numbers, email addresses, driver's license numbers, partial credit/debit card numbers (last 4 digits), and credit/debit card expiration dates. Approximately 500,000 individuals across all 50 U.S. states may have been affected. However, no full payment card details, CVVs, SSNs, or medical records were involved. The company has stated that there is no evidence of misuse of the compromised data. Three class-action lawsuits have been filed, and an MDL hearing is scheduled for April 2026.
It is important to note that details regarding data breaches can evolve as investigations continue and further information becomes available. Initial notifications may be followed by updates, or additional affected individuals may be identified.