Article Details
Scrape Timestamp (UTC): 2024-06-19 19:47:28.263
Original Article Text
Click to Toggle View
Advance Auto Parts confirms data breach exposed employee information. Advance Auto Parts has confirmed it suffered a data breach after a threat actor attempted to sell stolen data on a hacking forum earlier this month. Advance operates 4,777 stores and 320 Worldpac branches and serves 1,152 independently owned Carquest stores in the United States, Canada, Puerto Rico, the U.S. Virgin Islands, Mexico, and various Caribbean islands. Earlier this month, BleepingComputer reported that a threat actor named 'Sp1d3r' began selling data they claimed was stolen during the recent Snowflake data-theft attacks. BleepingComputer contacted Advance multiple times about the alleged data breach, but they never responded to our emails. However, in an SEC filing first spotted by security researcher pancak3, Advance Auto Parts confirmed that their data was stolen from a third-party cloud database environment. "On May 23, 2024, Advance Auto Parts, Inc. (the "Company") identified unauthorized activity within a third-party cloud database environment containing Company data and launched an investigation with industry-leading experts," reads the Form 8-K filing. "On June 4, 2024, a criminal threat actor offered what it alleged to be Company data for sale. The Company has notified law enforcement." After investigating the stolen files, Advance says they believe they contain personal information for current and former employees and job applicants, including social security numbers and other government identification numbers. Sample data leaked by the threat actor and seen by BleepingComputer also included employees' full names and email addresses. The data also included what is believed to be customer information, including email addresses and names. Advance says they will send data breach notifications to those impacted and offer free credit monitoring and identity restoration services as necessary. It is unclear if this will be only for employees at this time or for exposed customers as well. The company states that they have incurred $3 million in expenses due to the incident.
Daily Brief Summary
Advance Auto Parts has verified a data breach exposing personal information of employees and potentially customers.
The breach stemmed from unauthorized access to a third-party cloud database used by the company.
The incident was first noted on May 23, 2024, and confirmed when a hacker named 'Sp1d3r' attempted to sell the data in June.
Among the compromised data are social security numbers, government identification numbers, full names, and email addresses of employees and job applicants.
There is an indication that some customer data, including email addresses and names, may also have been exposed.
The company has contacted law enforcement, begun notifying affected parties, and is offering free credit monitoring and identity restoration services.
Advance Auto driven to spend around $3 million in response to the breach to mitigate its impacts and strengthen security measures.