Attack + Goal
April to May 2024 on Advance Auto Parts. Goal was corporate data theft and online extortion.
Result
380 million customer profiles, 140 million orders, and 2.3 million job applicant records stolen and leaked.
Method
Employee credential theft via infostealer malware
Financial Impact
Attacker demanded a $1.5 million ransom; official filings reveal $3 million in direct incident response costs.
Between April 14 and May 24, 2024, cybercriminals breached Advance Auto Parts' Snowflake cloud database environment, maintaining undetected access for over 40 days. The blast radius was massive, impacting 380 million customer profiles, 140 million order details, 44 million loyalty card numbers, and 2.3 million job applicants whose Social Security numbers and driver's licenses were exposed. An extortionist operating under the alias Sp1d3r stole 3 terabytes of sensitive data and listed the entire database for sale on a cybercrime forum for $1.5 million. The breach did not stem from a technical vulnerability in cloud infrastructure. Instead, the attackers used valid corporate login credentials previously harvested through infostealer malware installed on employee devices. The attackers logged in directly and systematically extracted the company's internal files.
Identify credentials harvested by infostealer malware at the source, catching the compromise and getting a remediation window before credentials are used to access platforms or listed for sale.