Advance Auto Parts is notifying more than 2.3 million people of a data breach resulting from the recent Snowflake.

On June 5, 2024, a threat actor known as “Sp1d3r” began selling a database (3 TB) that allegedly contained 380 million records . This database allegedly included order details, transaction details, and other sensitive information.
On June 19, the company confirmed the breach and said it only affected current and former employees and prospective employees.
See also: Dallas County: Data breach affects 200,000 people
The incident was part of a broader campaign targeting Snowflake accounts using stolen credentials. These attacks have affected several large companies, including Pure Storage, Los Angeles Unified, Neiman Marcus, Ticketmaster, and Banco Santander.
Employees were affected
Advance Auto Parts has completed its internal investigation and determined that the data breach ultimately impacted 2,316,591 million people . The threat actors appear to have been able to maintain unauthorized access to Advance’s Snowflake environment for over a month (as of mid-April 2024).
" Our investigation determined that an unauthorized individual accessed or copied certain information maintained by Advance Auto Parts from April 14, 2024, to May 24, 2024 ," the statement said
See also: Lulu Hypermarket data breach exposes thousands of users
The data stolen by the attackers includes full names, social security numbers (SSN), driver's licenses, and ID numbers.
The company says it collects this information as part of the job application process, so the 2.3 million figure relates to applicants job and former/current employees whose data was stored in the compromised cloud database.
The company offers free identity theft protection and credit monitoring services through Experian, for 12 months.

The 2.3 million figure reported by Advance Auto Parts is a far cry from the hackers' claims of 380 million files. Also, the types of data confirmed to have been exposed are not as extensive.
However, according to BleepingComputer, some samples of the stolen data appear to contain customer information.
See also: Evolve Bank & Trust: Data breach affects 7.6 million Americans
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This Advance Auto Parts data breach serves as a reminder of the importance of cybersecurity for businesses in today’s digital age. By continually evaluating and strengthening their security protocols, maintaining regulatory compliance, and investing in advanced technologies, companies can better protect themselves, their employees, and their customers from cyber threats. As technology continues to evolve, it is vital for businesses to remain vigilant.
Source: www.bleepingcomputer.com
