Back to all incidents

Advance Auto Parts

advanceautoparts.com
CONFIRMED

Automotive retailer Advance Auto Parts filed Form 8-K Item 1.05 after cybercriminals compromised its cloud database tenant, stealing 380 million customer profiles.

Observable Status CONFIRMED
Industry / Sector Retail & Consumer Goods
Incident Classification Third-Party Cloud Account Takeover
Attributed Threat Actor UNC5537
Affected Population 380,000,000 records
First Seen 2024-05-23
Last Updated 2024-06-05
Customer Profiles Social Security Numbers (SSNs) Driver License Numbers Purchasing & Loyalty Data
OPEN WEIGHTS TELEMETRY • DETERMINISTIC CONFIDENCE

Confidence & Source Corroboration

100% CONFIDENCE
1. Primary Authority CONFIRMED BY REGULATOR Base weight: 65%
2. Evidence Specificity +23% Statutory Filing Verified
3. Corroboration Curve +17% 3 independent domains
4. Timeline & Staleness +3% 3 milestones logged
Corroborated Source Domains:
corp.advanceautoparts.com cloud.google.com sec.gov
STATUTORY REGULATORY DISCLOSURES

Official Regulatory Filings & Legal Compliance Records

1 Verified Statutory Filing
Regulatory Ground Truth Standard: The disclosures below represent formal statutory filings and enforcement records submitted to government regulatory authorities (SEC, State Attorneys General, HHS OCR, CISA). In accordance with repository principles, this data is captured exactly as filed by the reporting entity and is never modified, overridden, or synthesized by AI models.
U.S. Securities and Exchange Commission (SEC)

Form 8-K Item 1.05 (Material Cybersecurity Incidents)

CONFIRMED BY REGULATOR
Docket / Accession ID 0001158449-24-000163
Statutory Filing Date 2024-06-05
Disclosed Impact 380,000,000 records
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Item 1.05 Material Cybersecurity Incident disclosure filed by Advance Auto Parts, Inc. regarding unauthorized access to third-party cloud data environment containing customer and employee records.

View Official Regulatory Filing Document https://www.sec.gov/Archives/edgar/data/1158449/000115844924000163/aap-20240605.htm

Technical Forensic Briefing

Incident Overview

Automotive retailer Advance Auto Parts filed Form 8-K Item 1.05 after cybercriminals compromised its cloud database tenant, stealing 380 million customer profiles.

Compromised Assets & Data Scope

  • Primary Data Classes: Customer Profiles, Social Security Numbers (SSNs), Driver License Numbers, Purchasing & Loyalty Data.
  • Disclosed Affected Population: Approximately 380,000,000 individuals or records.

Statutory Disclosures & Compliance

  • Statutory filing submitted to SEC (Form 8-K (Item 1.05)) under accession 0001158449-24-000163.

Milestone Timeline (3 events logged)

2024-05-23 16:30 UTC
CONFIRMED BY TARGET

Unauthorized actor accesses company's cloud data environment via stolen contractor credentials.

2024-06-04 18:00 UTC
INDEPENDENT VERIFICATION

Threat actor offers 380 million customer records for sale on dark web breach forums for $1.5 million.

2024-06-05 17:30 UTC
CONFIRMED BY REGULATOR

Advance Auto Parts files Form 8-K Item 1.05 confirming exfiltration of customer and employee data files.

Have updated information or a new verifiable source?

This incident record is a flat Markdown file tracked in Git. Propose an update or add a milestone via Pull Request.

Propose Update via GitHub