Advance Auto Parts
Disclosed Jun 14, 20242 years ago2,316,591 affectedConfirmed
Snowflake-linked breach exposes data of 2.3 million applicants and employees
Advance Auto Parts reported to the SEC that on May 23, 2024 it identified unauthorized activity in a third-party cloud database, and data was offered for sale on June 4. State filings later showed 2,316,591 current and former job applicants and employees had Social Security numbers, ID numbers and birth dates exposed.
What is known
| People affected | 2,316,591 (as reported by the organization) |
|---|---|
| Disclosed | Jun 14, 2024 |
| Discovered | May 23, 2024 |
| Happened | Jun 5, 2024 |
| Attack | Credential stuffing |
| Data exposed | Emails, Names, Phone numbers, Addresses, Social Security numbers, Government IDs, Dates of birth, Employment |
| Sector | Retail · US |
| Status | Confirmed |
| Part of | Snowflake (2024) |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| Have I Been Pwned: Advance Auto Partshaveibeenpwned.com · Aggregator | Aggregator |
| Advance Auto Parts says more than 2 million impacted by data breachtherecord.media · News | News |
| Advance Auto Parts Form 8-K (June 14, 2024)sec.gov · SEC filing | SEC filing |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jun 14, 2024 | 2,316,591 |
| Have I Been Pwnedaccounts in the data | Jun 24, 2024 | 79,243,727 |
Same campaign
Other breaches at Advance Auto Parts
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed Mar 15, 2016Mar 15, 201610 years agoPhishing | Mar 15, 201610 years ago | Phishing | Tech | Confirmed | Unknown |
History of this record
- 2026-09-25 · source_type: aggregator to filing · seed source
- 2026-09-25 · source_url: https://haveibeenpwned.com/Breach/AdvanceAutoParts to https://www.sec.gov/Archives/edgar/data/1158449/000115844924000162/aap-20240523.htm · seed source
- 2026-09-25 · status: disclosed to confirmed · seed source
- 2026-09-25 · verified_by: empty to research · seed source
- 2026-09-25 · verified: 0 to 1 · seed source
- 2026-09-25 · campaign: empty to snowflake-2024 · seed source
- 2026-09-25 · country: empty to US · seed source
- 2026-09-25 · sector: tech to retail · seed source
- 2026-09-25 · attack: insider to credential-stuffing · seed source
- 2026-09-25 · data_types: ["emails","names","phone","addresses"] to ["emails","names","phone","addresses","ssn","government-id","dob","employment"] · seed source
- 2026-09-25 · records_basis: hibp to organization · seed source
- 2026-09-25 · records: 79243727 to 2316591 · seed source
- 2026-09-25 · disclosed: 2024-06-24 to 2024-06-14 · seed source
- 2026-09-25 · discovered: empty to 2024-05-23 · seed source
- 2026-09-25 · summary: In June 2024, Advance Auto Parts confirmed they had suffered a data breach which was posted for sale to a popular hacking forum. Linked to unauthorised access to Snowflake cloud services, the breach exposed a large number of records related to Advance Auto Parts reported to the SEC that on May 23, 2024 it identified unauthorized activity in a third-party cloud database, and data was offered for sale on June 4. State filings later showed 2,316,591 current and former job applicants · seed source
- 2026-09-25 · title: empty to Snowflake-linked breach exposes data of 2.3 million applicants and employees · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Have I Been Pwned), confirmed by Research. Record counts are as reported. Not legal advice.