Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Santander confirmed a data breach. What did ShinyHunters’ “30 million customers” sale claim really mean?

Santander confirmed a third-party database intrusion, while a ShinyHunters-linked listing later claimed data on 30 million customers. The figure and detailed contents were not independently confirmed.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: Santander confirmed unauthorized access to a database hosted by a third-party provider on May 14, 2024. The bank identified customer information from Chile, Spain and Uruguay, along with information about current and some former employees. A later listing attributed to the ShinyHunters name claimed to offer data on 30 million Santander customers, but Santander did not confirm that number, the detailed inventory or a completed sale.

What Santander confirmed on May 14, 2024

In its public statement, Santander said an attacker gained unauthorized access to a database hosted by a third-party provider. The affected customer records related to Chile, Spain and Uruguay. Information about all current Santander employees and some former employees was also involved, according to the bank.

Santander said customer data in its other markets and businesses was not affected and that its banking operations and systems were not compromised. The bank also said the database did not contain transactional data, online-banking details or passwords capable of authorizing transactions. Santander reported that it blocked the access, added fraud-prevention controls, contacted affected people and notified regulators and law enforcement. Read Santander’s statement.

Where the “30 million” figure came from

At the end of May 2024, a cybercrime-forum listing attributed to a threat actor using the ShinyHunters name advertised purported Santander data. Contemporaneous reporting said the seller claimed to have:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Figure in the listing How to interpret it
30 million customer records A seller’s claim, not a customer count confirmed by Santander
About 6 million account numbers and balances Reportedly advertised fields; not independently confirmed by Santander
About 28 million credit-card numbers Reportedly advertised fields; not independently confirmed by Santander
Approximately $2 million Reported asking price in contemporaneous reporting

“Records” and “customers” are not interchangeable. The advertised figures could include overlapping datasets, repeated records or different fields referring to the same people. They do not establish that 30 million unique Santander customers were affected. The listing’s existence also does not prove that every claimed field was genuine or that a buyer completed a purchase. Ars Technica reported on the listing.

Confirmed facts versus marketplace allegations

Confirmed by Santander Claimed by the seller or reported from the listing
Unauthorized access to a third-party-hosted database occurred Data on 30 million customers
Customer information from Chile, Spain and Uruguay was accessed About 6 million account numbers and balances
Information about current and some former employees was accessed About 28 million credit-card numbers
The database lacked transactional data and transaction-capable online-banking credentials, according to Santander An asking price of approximately $2 million
Santander said other markets’ customer data was not affected A completed sale, which has not been established by the sources cited here

Who are ShinyHunters?

ShinyHunters is a cybercrime alias associated with data theft, extortion and leak-forum activity. For this incident, the careful description is that a listing attributed to ShinyHunters claimed to offer Santander data. An alias does not necessarily represent one stable organization, and Santander’s statement did not publicly identify ShinyHunters as the intruder.

The incident was discussed alongside a broader 2024 campaign tracked by Google and Mandiant as UNC5537. That technical label describes campaign activity; it is not proof that every listing carrying the ShinyHunters name was produced by the same people. Google Cloud and Mandiant’s analysis provides the campaign context.

Was Snowflake breached?

It is misleading to reduce the episode to “Snowflake was hacked.” Snowflake, Mandiant and CrowdStrike said they found no evidence that a vulnerability, misconfiguration or breach of Snowflake’s own platform caused the campaign. They described targeted customer accounts, particularly accounts using single-factor authentication, accessed with credentials that had previously been stolen or obtained through infostealing malware. They also said there was no evidence that current or former Snowflake personnel credentials caused the activity. Snowflake’s security updates set out those findings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This distinction does not remove customer or supplier responsibility. A cloud platform can lack a newly exploited platform vulnerability while a customer account, password or access policy is still compromised. Multifactor authentication, network restrictions, credential rotation and monitoring are important controls for those customer environments.

What information was exposed?

What Santander publicly described

Santander confirmed that certain information relating to customers in the three named countries and to employees was accessed. Its public statement did not provide a complete field-by-field inventory.

What the seller alleged

The 30-million, 6-million and 28-million figures came from the reported marketplace advertisement. They should be treated as allegations, not as a confirmed list of stolen fields.

What Santander said was not in the database

Santander said the database did not contain transactional data, online-banking details or passwords that could authorize transactions. That is different from saying the exposed information was harmless. Names, contact details, employment information and other personal data can make phishing, impersonation and identity-fraud attempts more convincing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which Santander customers should be concerned?

Santander’s identified customer markets were Chile, Spain and Uruguay. The statement did not say that all Santander customers worldwide, or specifically Santander UK customers, were included. Santander said customer data in its other markets and businesses was not affected. People should therefore rely on a direct notice from their own Santander entity rather than infer exposure from the “30 million” headline.

Practical risks for customers

  • Targeted emails, texts or calls pretending to be Santander.
  • Fraudsters using accurate personal details to appear credible.
  • Requests for one-time passcodes, passwords, card details, PINs or security codes.
  • Social engineering aimed at customers, employees or their contacts.
  • Identity-theft attempts if enough identifying information was exposed.

Santander said it would not ask customers for passwords or one-time codes. A message containing correct personal details can still be fraudulent; accuracy is not authentication.

What to do if you may be affected

  1. Check through an official channel. Use Santander’s official website, app or telephone number, not a link or number supplied in an unsolicited message.
  2. Disclose no authentication secrets. Never give a caller or texter your password, one-time passcode, PIN or security code.
  3. Review activity. Check account transactions, cards and payees for anything unfamiliar.
  4. Report suspicious activity immediately. Contact Santander through its official channel if you see an unauthorized transaction or suspect account manipulation.
  5. Replace reused passwords. Change any password shared with another service, beginning with email and other accounts that can reset financial access.
  6. Turn on multifactor authentication. Use phishing-resistant MFA where a service supports it, and secure your email and password manager first.
  7. Report phishing. Use Santander’s official reporting process and the relevant national reporting authority.
  8. Consider monitoring based on your circumstances. Credit or identity monitoring can provide alerts, but it cannot stop a real-time transfer, prevent every phishing attack or guarantee removal of data from criminal markets.

Do not automatically freeze a bank account or replace every card unless Santander instructs you to do so or you have evidence of payment-card exposure.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What happened after disclosure?

Santander said it blocked the compromised access, introduced additional fraud controls, contacted affected customers and employees, and notified regulators and law enforcement. A UK Information Commissioner’s Office disclosure-log entry records a May 23, 2025 request about the investigation, outcome and action involving Santander UK. The entry partially withheld information; it is not a finding that Santander UK was fined or that UK customer data was exposed. See the ICO disclosure log.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What remains unknown

  • Whether all data advertised in the forum listing was genuine.
  • Whether “30 million” represented unique people rather than records or fields.
  • Whether a buyer obtained the advertised dataset.
  • The complete field-level contents of the accessed database.
  • Whether a later regulatory or court finding materially changed the public account.

The sources cited here do not establish a final regulatory penalty, ransom payment or completed sale.

Bottom line

Santander suffered a real unauthorized database access incident, but the strongest headline—30 million Santander customers for sale—came from an unverified criminal-marketplace claim. The confirmed geography was Chile, Spain and Uruguay, plus current and some former employees; Santander said transaction data and transaction-capable credentials were not present. Treat unexpected Santander-themed contact as a phishing risk, verify through official channels and do not confuse a seller’s advertised inventory with an independently confirmed customer count.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.