Avis has established a $3,075,000 settlement fund to compensate customers whose personal information was stolen during a data breach affecting approximately 299,006 people who rented vehicles from the company. The breach occurred between August 3 and 6, 2024, when someone with inside access to Avis’s systems extracted customer data including names, driver’s license numbers, credit card information, dates of birth, and phone numbers.
If you rented a car from Avis during that period and received a notification letter dated September 4, 2024, you may be eligible to file a claim for up to $5,000 in compensation. This settlement represents one of the more significant breaches affecting the car rental industry, and the compensation available reflects both the scope of the exposure and the types of sensitive personal information that criminals could use to commit identity theft or fraud. Customers whose information was compromised can submit claims online or by mail, with a deadline of June 21, 2026, to receive their share of the settlement fund.
Table of Contents
- What Happened in the Avis Rental Car Company Data Breach?
- What Personal Information Was Stolen in the Avis Data Breach?
- How Much Money Is in the Avis Settlement and Who Receives It?
- How Do You File a Claim for the Avis Settlement?
- Who Is Eligible to Receive Compensation from This Settlement?
- Key Deadlines and Court Approval Timeline
- What Happens After You File Your Claim?
What Happened in the Avis Rental Car Company Data Breach?
Between August 3 and 6, 2024, an insider with access to Avis’s computer systems exploited that access to steal customer information. The company discovered the unauthorized access on August 5, 2024, during the breach window itself. Avis’s investigation concluded that the breach resulted from “insider wrongdoing,” meaning someone employed by or with legitimate system access through Avis intentionally extracted customer data.
This type of breach is particularly concerning because it bypasses many external security measures that companies rely on to protect against hackers. The insider threat represents a vulnerability that’s difficult for companies to prevent entirely, since legitimate employees have authorized access to customer databases. While major retailers and service providers invest heavily in monitoring and access controls, a determined employee or contractor with the right credentials can still export large volumes of data quickly. Avis notified affected customers by sending notice letters dated September 4, 2024, giving customers roughly a month to understand what information had been compromised before the settlement claim process became available.
What Personal Information Was Stolen in the Avis Data Breach?
The stolen data included names, driver’s license information, credit card numbers and expiration dates, dates of birth, and phone numbers. This combination of information is particularly dangerous because criminals can use it to impersonate victims when opening new accounts, accessing existing financial services, or committing fraud. Unlike a breach limited to email addresses or customer IDs, this incident exposed the core information needed for identity theft.
A customer whose driver’s license number, date of birth, and credit card information were stolen faces specific risks: someone could attempt to open a new line of credit using the stolen card details, apply for a loan or credit card in the victim’s name using the driver’s license and date of birth, or contact financial institutions posing as the affected customer. The inclusion of phone numbers makes it easier for criminals to conduct social engineering attacks, calling the customer’s bank while pretending to be them. Because all three categories of sensitive data were exposed together, the risk of coordinated fraudulent activity is higher than if only one data type had been stolen.
How Much Money Is in the Avis Settlement and Who Receives It?
The settlement fund totals $3,075,000 in compensation available to affected customers. This is a non-reversionary fund, meaning any money remaining after valid claims are paid will not revert to Avis but will instead be distributed to claimants. Eligible customers can receive up to $5,000 each to cover documented out-of-pocket losses directly resulting from the data breach—such as fraud on stolen credit cards, identity theft recovery costs, or credit monitoring fees incurred after the breach notification.
The per-claim maximum of $5,000 is designed to compensate for concrete financial harm directly tied to the breach. This means claims for general worry, stress, or potential future identity theft typically won’t be compensated; instead, the settlement prioritizes people who can document actual losses. If 299,006 people filed claims and divided the full settlement equally, each would receive roughly $10, but in practice, the distribution depends on which customers file claims and what documented losses they can prove. The non-reversionary structure means that any unused settlement money gets distributed to claimants rather than going back to Avis, creating an incentive for the settlement administrator to ensure eligible people know about the claim process.
How Do You File a Claim for the Avis Settlement?
Customers can file claims online or by mail, with both methods having the same deadline: June 21, 2026. Online claims must be submitted by the deadline date, while mailed claim forms must be postmarked by June 21, 2026—meaning you need to account for mail delivery time if you’re sending it through the postal service. The settlement website or settlement administrator’s contact information should be included in the September 4, 2024 notice letter, or you can search for “Avis data breach settlement” to locate the official claim portal.
📨 Get Free Mass Tort Guides Alerts
Free · No spam · Unsubscribe anytime
When filing, you’ll need to provide proof of your loss—typically documentation like credit card statements showing unauthorized charges, receipts for credit monitoring services purchased after the breach, or correspondence from financial institutions regarding fraud claims. The more specific documentation you can provide, the stronger your claim for compensation. Some customers may not have experienced any out-of-pocket losses at all; in those cases, many settlement administrators allow you to submit a claim based solely on time spent addressing the breach, though the compensation for time is typically modest compared to claims for documented financial harm.
Who Is Eligible to Receive Compensation from This Settlement?
You’re eligible if you’re a customer who rented a vehicle from Avis between August 3 and 6, 2024, and your personal information was included in the breach. The company’s notification letter dated September 4, 2024, serves as official notification that your data was compromised. If you didn’t receive such a letter, you likely weren’t affected by this particular breach, though you can verify by checking whether you rented from Avis during those specific three days.
One limitation of this settlement is that children under 18 may face restrictions on claiming benefits directly, and claims may need to go through a parent or legal guardian. Additionally, if you received a notice letter but later discovered you didn’t actually rent from Avis during the breach window, you wouldn’t be eligible. The settlement applies only to those whose information was actually included in what the insider extracted, not to all Avis customers during that period—the company conducted an investigation to determine which customer records were actually accessed.
Key Deadlines and Court Approval Timeline
The claim filing deadline is June 21, 2026, by which time online claims must be submitted and mailed claim forms must be postmarked. The settlement is scheduled for final approval at a hearing in federal court in New Jersey on July 28, 2026. This timeline gives affected customers roughly 18 months from the settlement’s establishment to gather documentation of losses and submit their claims.
The final approval hearing date is important because it represents when the court will officially approve the settlement, evaluate whether settlement terms are fair, and address any objections that have been filed. After final approval, the settlement administrator will process valid claims and distribute compensation to eligible claimants. If the hearing goes forward on July 28, 2026, as scheduled, claim payouts would typically follow within several months afterward.
What Happens After You File Your Claim?
Once you submit a claim, the settlement administrator will review your documentation to verify that you meet the eligibility requirements and that your claimed losses are properly documented. If your claim is accepted, you’ll receive compensation from the settlement fund. The timing of payments depends on the volume of claims received and how quickly the administrator can process them; settlements of this size sometimes take several months to complete claim processing after the deadline passes.
If your claim is denied, you typically have the right to appeal within a specified timeframe, providing additional documentation or information to support your case. Keep copies of all documentation you submit with your claim, and maintain records of the claim submission number or receipt if one is provided. After June 21, 2026, customers who miss the deadline generally cannot file claims and lose the opportunity to receive compensation from this settlement, though each person’s circumstances differ and some limited exceptions may exist through the settlement administrator’s procedures.
- —
You Might Also Like
- Comcast Data Breach Settlement Covers Customers Affected by Security Incident
- Geisinger Health Data Settlement Covers Patients Affected by Employee Data Access Incident
- Fidelity Investments Data Breach Settlement Covers Customers Whose Information Was Exposed