A threat actor claimed to be selling 3TB of data allegedly belonging to Advance Auto Parts from its Snowflake data warehouse. The company confirmed the breach, which impacted over 2.3 million individuals, primarily employees. The data purportedly included customer and employee information, purchase histories, loyalty/gas card numbers, and employment-related details.
Specific data types exposed include names, email addresses, mobile and phone numbers, addresses, purchase histories, loyalty/gas card numbers, employment details, auto parts information, sales history, employment candidate information (including SSNs and driver's license numbers), demographic details, and transaction tender details. The estimated number of affected individuals is over 2.3 million. The extent of customer data exposure beyond what the threat actor claimed remains unclear, as the company's confirmation focused on employee information.
This incident is part of broader attacks targeting Snowflake customers. Advance Auto Parts has begun notifying affected individuals.