01Summary
In 2024, Advance Auto Parts was among dozens of companies affected by a broad campaign targeting Snowflake cloud storage customers. The attackers, tracked by Mandiant as UNC5537, used stolen credentials to access Snowflake instances lacking multi-factor authentication. Advance Auto Parts confirmed that 2.3 million records were compromised, including customer names, email addresses, phone numbers, and employee data such as names and Social Security numbers of current and former employees.
02Background
Advance Auto Parts is a leading automotive aftermarket parts retailer with over 4,700 stores in the United States and Canada.
03Key revelations
- 01Snowflake security configurations were a common weakness across dozens of breaches
- 02Info-stealer malware was the root cause of credential compromise
- 03Lack of MFA on enterprise cloud data warehouses created systemic risk
04Technical analysis
Attackers used credentials obtained from info-stealer malware infections targeting Snowflake employees and customers. The compromised Snowflake instances lacked MFA and had network access controls that were insufficiently restrictive. Once inside, attackers exfiltrated data using Snowflake's own COPY INTO commands to transfer data to attacker-controlled storage.
05Threat actor
UNC5537 (Mandiant designation) is a financially motivated threat actor group that systematically targeted Snowflake customer instances. They operated with patience and sophistication, using stolen credentials rather than exploiting technical vulnerabilities, demonstrating the effectiveness of credential-based attacks against poorly configured cloud services.
Aliases
- Snowflake Attacker
- UNC5537
MITRE groups
- UNC5537
Attribution sources
- Mandiant investigation
- Snowflake disclosure
- Media reports
06Victims and impact
Exposure of customer PII and employee SSNs created risks of identity theft and targeted phishing. Advance Auto Parts faced potential regulatory actions under state data breach notification laws.
Evidence of breach
The attackers attempted to extort Advance Auto Parts and posted samples of the stolen data online. Mandiant confirmed the breach as part of a coordinated campaign.
Additional victims
- Snowflake (cloud provider)
Countries affected
- United States
- Canada
07Data exposed
Data types
- Customer Names
- Email Addresses
- Phone Numbers
- Physical Addresses
- Employee Names
- Employee SSNs
- Purchase History
08Financial damage
Costs included incident response, customer notification, legal fees, and potential regulatory penalties.
09Timeline
- 2024-04-01Initial compromise via stolen Snowflake credentials (estimated)
- 2024-05-20Mandiant discovers broader Snowflake campaign
- 2024-06-10Advance Auto Parts confirms breach
- 2024-06-15Company begins notifying affected individuals
10Reaction and fallout
Public reaction
Concern among customers and employees about the exposure of SSNs and the broader Snowflake supply chain risk.
Political impact
Contributed to regulatory scrutiny of cloud security practices and MFA requirements for enterprise data platforms.
11Legal
Potential class-action lawsuits and regulatory investigations under state and federal data protection laws.
12Aftermath
Policy changes
- Snowflake mandated MFA for all customer accounts following the breach campaign
Security improvements
- MFA enforcement on cloud data platforms
- Credential rotation and monitoring for info-stealer infections
13Significance and legacy
Significance
The Advance Auto Parts breach was part of one of the largest cloud data theft campaigns in 2024, demonstrating the cascading risks of credential theft targeting cloud infrastructure providers.
Legacy
Contributed to industry-wide implementation of mandatory MFA on cloud data platforms and increased awareness of info-stealer malware risks targeting enterprise cloud credentials.
14Disclosure and media
- Authentication
- Mandiant investigation report and independent verification
Publishing organisations
- BleepingComputer
- Mandiant
- TechCrunch
- Bloomberg
16Field notes
- 01The Snowflake campaign affected over 160 customers, making it one of the largest cloud data theft operations in history.
- 02The attackers specifically targeted companies using Snowflake WITHOUT multi-factor authentication.
17Resolution
Advance Auto Parts engaged incident response teams, notified affected individuals, and implemented enhanced security measures including MFA on all cloud accounts.
18Sources
Official documents
- Advance Auto Parts data breach notification to regulators
References
- [1]Mandiant investigation report
- [2]BleepingComputer
- [3]TechCrunch
- [4]Snowflake security advisory









