Advance Auto Parts
On 5 June 2024, Advance Auto Parts was breached. 79,243,727 accounts were exposed, including email addresses, names, phone numbers. MyRecon rates it 74/100 — severe. That is roughly everyone in the United Kingdom.
This belongs to a set rather than standing alone. Through mid-2024 a long run of large companies disclosed breaches traced to their own cloud data warehouse tenants — accounts reached with credentials stolen earlier by malware, on tenants where multi-factor authentication was not enforced. The platform itself was not compromised. The customers' configurations of it were.
It is the clearest illustration available of what shared responsibility means in practice. The provider secures the service; the customer secures access to their instance. Where that line sits is written in documentation nobody reads until a quarter of a billion records have moved, and in 2024 a great many organisations discovered which side of it they had been standing on.
The full case file covers how the campaign worked and why so many companies fell in the same few weeks.
What happened
In June 2024, Advance Auto Parts confirmed they had suffered a data breach which was posted for sale to a popular hacking forum. Linked to unauthorised access to Snowflake cloud services, the breach exposed a large number of records related to both customers and employees. In total, 79M unique email addresses were included in the breach, alongside names, phone numbers, addresses and further data attributes related to company employees.
Breach description from Have I Been Pwned, used under a CC BY 4.0 licence.
Who was behind it
No party has been publicly confirmed as responsible, and this page will not name one. Most breaches are never formally attributed: data surfaces on a forum or inside a combined dump long after the intrusion, and the trail back to a specific actor is rarely made public. Where a group has claimed responsibility it is usually named in the account above — that claim is theirs, not a finding of ours.
What was exposed, and why it matters
- Email addressesThe address becomes a confirmed, active target — expect more phishing, better aimed.
- NamesTurns an anonymous address into an identified person, which is what makes targeted phishing possible.
- Phone numbersEnables SIM-swap attacks against SMS two-factor codes, and puts the number on scam-call lists indefinitely.
- Physical addressesWhere someone actually lives. Combined with a name this moves the risk off the internet.
What to do if you were in it
- Move two-factor authentication off SMS and onto an authenticator app, which a SIM swap cannot intercept.
- Be sceptical of post and callers who already know your address — knowing it is no longer evidence of anything.
- Expect better-aimed phishing. A message that already knows your name and where you have an account is the whole point of a breach like this.
Questions people ask about this breach
Was my email address in the Advance Auto Parts breach?
Enter it in the box at the top of this page. MyRecon checks it against this breach and every other one on record, and the address is never stored.
What data was leaked in the Advance Auto Parts breach?
email addresses, names, phone numbers, physical addresses. Each one is explained above, along with what it means for the person it belongs to.
When did it happen, and when did it become public?
The breach is dated 5 June 2024. It was published to Have I Been Pwned on 24 June 2024, a gap of 19 days during which the data was already out.
Is the Advance Auto Parts breach real?
Yes. Have I Been Pwned lists it as verified, meaning the data was checked against the source rather than taken on trust.
How many people were affected?
79,243,727 accounts. That is roughly everyone in the United Kingdom. That is accounts rather than people — one person often has several.
Read next
Also in the archive
Case Files: how the landmark breaches actually happened →
Three kinds of content appear on this page and they are kept apart deliberately. The breach description is quoted from Have I Been Pwned under its licence. The severity score, the field-by-field explanation and the advice are computed from the record itself — every sentence derives from a number or a flag in it, which is what stops the analysis drifting from the evidence. Anything under the "MyRecon's take" byline is editorial: our reading of this breach, presented as opinion rather than as a finding.