Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Millions Impacted by Breach at Advance Auto Parts Linked to Snowflake Incident

Advance Auto Parts says the personal information of 2.3 million was compromised after hackers accessed its Snowflake account.

American automotive aftermarket parts provider Advance Auto Parts is notifying over 2.3 million individuals that their personal information was compromised in the Snowflake incident earlier this year.

As part of the Snowflake campaign, threat actors used stolen credentials harvested using information stealer on non-Snowflake systems to access the accounts of roughly 165 customer accounts at the cloud storage provider.

Starting mid-April, the attackers accessed Snowflake accounts that lacked multi-factor authentication (MFA) protections and network allow lists, and then attempted to extort the victim organizations by threatening to leak the stolen data.

On July 10, Advance Auto Parts disclosed to the Maine Attorney General’s Office that the personal information of 2,316,591 individuals was stolen from its Snowflake account and that it has started sending data breach notifications.

The compromised personal information, the company says, includes names, dates of birth, Social Security numbers, driver’s license numbers, and other government-issued identification numbers.

In a notification letter to the impacted individuals, a copy of which was submitted to the Maine AGO, Advance Auto Parts explained that the attackers accessed and copied data from its Snowflake account between April 14 and May 24.

Advertisement. Scroll to continue reading.

“Upon learning of the incident, we promptly terminated the unauthorized access and took proactive measures aimed at preventing future unauthorized access. We also notified law enforcement,” the notification letter reads.

Advance Auto Parts is providing the impacted individuals with 12 months of free credit monitoring and identification theft protection services.

The Snowflake campaign also impacted Anheuser-Busch, Allstate, Los Angeles Unified, Mitsubishi, Neiman Marcus, Progressive, Pure Storage, State Farm, Santander Bank, and Ticketmaster.

Australia-based live events and ticketing firm Ticketek Entertainment Group (TEG) might have been affected as well.

Related: Evolve Bank Data Breach Impacts 7.6 Million People

Related: Prudential Financial Data Breach Impacts 2.5 Million

Related: Apple Commissions Study to Highlight Need for End-to-End Encryption

Related: State Bar of Georgia Confirms Breach From Ransomware Attack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.