EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2024-advance-auto-parts-breach
102/430

File EL-0329HighResolvedData Breach / Third-Party Cloud Exploitation

Advance Auto Parts Data Breach

Also filed as Advance Auto Parts Snowflake Breach

Advance Auto Parts suffered a data breach as part of a broader campaign targeting Snowflake customers. Over 2.3 million records including customer PII and employee data were exfiltrated.

  • #retail
  • #automotive
  • #pii
  • #snowflake
  • #cloud-security
  • #credentials
  • #employee-data
Notoriety7/10
Event
1 Apr 2024
Disclosed
10 Jun 2024
Target
Advance Auto Parts
Actor
UNC5537 / Snowflake Extortion Group
Scale
2.3M people
Status
Resolved

01Summary

In 2024, Advance Auto Parts was among dozens of companies affected by a broad campaign targeting Snowflake cloud storage customers. The attackers, tracked by Mandiant as UNC5537, used stolen credentials to access Snowflake instances lacking multi-factor authentication. Advance Auto Parts confirmed that 2.3 million records were compromised, including customer names, email addresses, phone numbers, and employee data such as names and Social Security numbers of current and former employees.

02Background

Advance Auto Parts is a leading automotive aftermarket parts retailer with over 4,700 stores in the United States and Canada.

03Key revelations

  1. 01Snowflake security configurations were a common weakness across dozens of breaches
  2. 02Info-stealer malware was the root cause of credential compromise
  3. 03Lack of MFA on enterprise cloud data warehouses created systemic risk

04Technical analysis

Attackers used credentials obtained from info-stealer malware infections targeting Snowflake employees and customers. The compromised Snowflake instances lacked MFA and had network access controls that were insufficiently restrictive. Once inside, attackers exfiltrated data using Snowflake's own COPY INTO commands to transfer data to attacker-controlled storage.

05Threat actor

UNC5537 (Mandiant designation) is a financially motivated threat actor group that systematically targeted Snowflake customer instances. They operated with patience and sophistication, using stolen credentials rather than exploiting technical vulnerabilities, demonstrating the effectiveness of credential-based attacks against poorly configured cloud services.

Aliases

  • Snowflake Attacker
  • UNC5537

MITRE groups

  • UNC5537

Attribution sources

  • Mandiant investigation
  • Snowflake disclosure
  • Media reports

06Victims and impact

Exposure of customer PII and employee SSNs created risks of identity theft and targeted phishing. Advance Auto Parts faced potential regulatory actions under state data breach notification laws.

Evidence of breach

The attackers attempted to extort Advance Auto Parts and posted samples of the stolen data online. Mandiant confirmed the breach as part of a coordinated campaign.

Additional victims

  • Snowflake (cloud provider)

Countries affected

  • United States
  • Canada

07Data exposed

Data types

  • Customer Names
  • Email Addresses
  • Phone Numbers
  • Physical Addresses
  • Employee Names
  • Employee SSNs
  • Purchase History

08Financial damage

Costs included incident response, customer notification, legal fees, and potential regulatory penalties.

09Timeline

  1. 2024-04-01Initial compromise via stolen Snowflake credentials (estimated)
  2. 2024-05-20Mandiant discovers broader Snowflake campaign
  3. 2024-06-10Advance Auto Parts confirms breach
  4. 2024-06-15Company begins notifying affected individuals

10Reaction and fallout

Public reaction

Concern among customers and employees about the exposure of SSNs and the broader Snowflake supply chain risk.

Political impact

Contributed to regulatory scrutiny of cloud security practices and MFA requirements for enterprise data platforms.

11Legal

Potential class-action lawsuits and regulatory investigations under state and federal data protection laws.

12Aftermath

Policy changes

  • Snowflake mandated MFA for all customer accounts following the breach campaign

Security improvements

  • MFA enforcement on cloud data platforms
  • Credential rotation and monitoring for info-stealer infections

13Significance and legacy

Significance

The Advance Auto Parts breach was part of one of the largest cloud data theft campaigns in 2024, demonstrating the cascading risks of credential theft targeting cloud infrastructure providers.

Legacy

Contributed to industry-wide implementation of mandatory MFA on cloud data platforms and increased awareness of info-stealer malware risks targeting enterprise cloud credentials.

14Disclosure and media

Authentication
Mandiant investigation report and independent verification

Publishing organisations

  • BleepingComputer
  • Mandiant
  • TechCrunch
  • Bloomberg

15Related files

Related events

  • 2024-snowflake-data-breach-2024
  • 2024-ticketmaster-breach-2024
  • 2024-change-healthcare-attack

16Field notes

  1. 01The Snowflake campaign affected over 160 customers, making it one of the largest cloud data theft operations in history.
  2. 02The attackers specifically targeted companies using Snowflake WITHOUT multi-factor authentication.

17Resolution

Advance Auto Parts engaged incident response teams, notified affected individuals, and implemented enhanced security measures including MFA on all cloud accounts.

18Sources

Official documents

  • Advance Auto Parts data breach notification to regulators

References

  1. [1]Mandiant investigation report
  2. [2]BleepingComputer
  3. [3]TechCrunch
  4. [4]Snowflake security advisory
Fact sheetEL-0329

Dates

Event
1 Apr 2024
Started
1 Apr 2024
Ended
15 May 2024
Duration
60 days
Discovered
20 May 2024
Disclosed
10 Jun 2024
Ongoing
No

Target

Organisation
Advance Auto Parts, Inc.
Type
Retail Company
Sector
Automotive Retail
Country
United States

Actor

Name
UNC5537 / Snowflake Extortion Group
Type
Criminal Gang
Motivation
Financial extortion through data theft from Snowflake customers
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
2,300,000
Sensitivity
Highly Sensitive
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.