HackingStolen CredentialsSupply Chain (3P Vendor)Employee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
ADVANCE STORES COMPANY, INCORPORATED
bd_b687cfd83b56a492 · schema v1 · pii pii-v1
Full breach record for ADVANCE STORES COMPANY, INCORPORATED →Advance Stores Company, Incorporated (Advance Auto Parts) disclosed that an unauthorized third party accessed information stored in Snowflake, its cloud vendor, from April 14 to May 24, 2024. The company learned of the incident on May 23, 2024. Affected data includes names, Social Security numbers, driver's license numbers, and dates of birth for job applicants. The company terminated access, notified law enforcement, engaged cybersecurity experts, and offered credit monitoring.
California clockDiscovered May 23, 2024 → Notified Jul 10, 202448d ✓ CA 60-day OK7 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_2136d1e78c22a08fVermont State AGfiled 2024-07-10Verified
- bd_699d2fe90e095368Delaware State AGfiled 2024-07-10Candidate
- bd_879fd3f910e4606aNew Hampshire State AGfiled 2024-07-10Verified
- bd_bc5881d478a60678Oregon State AGfiled 2024-07-10Verified
Show 1 more filing ↓Show fewer ↑
- bd_ca64838043f7afceMaine State AGfiled 2024-07-10Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-588394
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 10, 2024
- Raw hash
- 93aa2d4782c026fe11907a3c8b2b75b14ccf5b1215e86e2d8def5d0edc2e86e2
Reporting entity
- Name
- ADVANCE STORES COMPANY, INCORPORATEDnorm: advance stores
Victim entity
- Name
- ADVANCE STORES COMPANY, INCORPORATEDnorm: advance stores
Incident
- Discovered
- May 23, 2024
- Materiality determined
- —
- Notification sent
- Jul 10, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via Snowflake
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 48d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 23, 2024→ Notified: Jul 10, 202448d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.