Advance Auto Parts notifies 2.3 million after Snowflake-linked breach

Organization
Advance Auto Parts
Exploit
Credential Compromise
Industry
Retail

Advance Auto Parts began notifying regulators and individuals in July 2024 that personal data had been taken from its environment on Snowflake, the third-party cloud data platform. In a filing with the Maine Attorney General's Office dated 10 July 2024, the retailer put the number of affected people at 2,316,591.

The company said an unauthorized party had access between 14 April and 24 May 2024. The exposed information included full names, dates of birth, Social Security numbers, driver's license numbers and other government-issued identification numbers. Infosecurity Magazine reported that those affected were primarily job applicants and current and former employees rather than retail customers, consistent with the company's earlier Form 8-K.

The incident formed part of a campaign against roughly 165 Snowflake customer tenants. Investigators at Mandiant traced it to credentials stolen by infostealer malware running on systems outside Snowflake, and found that the targeted accounts lacked multifactor authentication and network allow lists.

A month before the notification, a threat actor using the handle Sp1d3r had advertised a three-terabyte database said to contain 380 million Advance Auto Parts customer records, initially seeking $1.5 million for it. The figures the company reported to regulators were far smaller. Advance Auto Parts offered affected individuals 12 months of credit monitoring and identity theft protection.

Sources