Recommended Free Tools
Short answer: Santander confirmed unauthorized access to a database hosted by a third-party provider on May 14, 2024. The bank identified customer information from Chile, Spain and Uruguay, along with information about current and some former employees. A later listing attributed to the ShinyHunters name claimed to offer data on 30 million Santander customers, but Santander did not confirm that number, the detailed inventory or a completed sale.
What Santander confirmed on May 14, 2024
In its public statement, Santander said an attacker gained unauthorized access to a database hosted by a third-party provider. The affected customer records related to Chile, Spain and Uruguay. Information about all current Santander employees and some former employees was also involved, according to the bank.
Santander said customer data in its other markets and businesses was not affected and that its banking operations and systems were not compromised. The bank also said the database did not contain transactional data, online-banking details or passwords capable of authorizing transactions. Santander reported that it blocked the access, added fraud-prevention controls, contacted affected people and notified regulators and law enforcement. Read Santander’s statement.
Where the “30 million” figure came from
At the end of May 2024, a cybercrime-forum listing attributed to a threat actor using the ShinyHunters name advertised purported Santander data. Contemporaneous reporting said the seller claimed to have:
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
| Figure in the listing | How to interpret it |
|---|---|
| 30 million customer records | A seller’s claim, not a customer count confirmed by Santander |
| About 6 million account numbers and balances | Reportedly advertised fields; not independently confirmed by Santander |
| About 28 million credit-card numbers | Reportedly advertised fields; not independently confirmed by Santander |
| Approximately $2 million | Reported asking price in contemporaneous reporting |
“Records” and “customers” are not interchangeable. The advertised figures could include overlapping datasets, repeated records or different fields referring to the same people. They do not establish that 30 million unique Santander customers were affected. The listing’s existence also does not prove that every claimed field was genuine or that a buyer completed a purchase. Ars Technica reported on the listing.
Confirmed facts versus marketplace allegations
| Confirmed by Santander | Claimed by the seller or reported from the listing |
|---|---|
| Unauthorized access to a third-party-hosted database occurred | Data on 30 million customers |
| Customer information from Chile, Spain and Uruguay was accessed | About 6 million account numbers and balances |
| Information about current and some former employees was accessed | About 28 million credit-card numbers |
| The database lacked transactional data and transaction-capable online-banking credentials, according to Santander | An asking price of approximately $2 million |
| Santander said other markets’ customer data was not affected | A completed sale, which has not been established by the sources cited here |
Who are ShinyHunters?
ShinyHunters is a cybercrime alias associated with data theft, extortion and leak-forum activity. For this incident, the careful description is that a listing attributed to ShinyHunters claimed to offer Santander data. An alias does not necessarily represent one stable organization, and Santander’s statement did not publicly identify ShinyHunters as the intruder.
The incident was discussed alongside a broader 2024 campaign tracked by Google and Mandiant as UNC5537. That technical label describes campaign activity; it is not proof that every listing carrying the ShinyHunters name was produced by the same people. Google Cloud and Mandiant’s analysis provides the campaign context.
Was Snowflake breached?
It is misleading to reduce the episode to “Snowflake was hacked.” Snowflake, Mandiant and CrowdStrike said they found no evidence that a vulnerability, misconfiguration or breach of Snowflake’s own platform caused the campaign. They described targeted customer accounts, particularly accounts using single-factor authentication, accessed with credentials that had previously been stolen or obtained through infostealing malware. They also said there was no evidence that current or former Snowflake personnel credentials caused the activity. Snowflake’s security updates set out those findings.
This distinction does not remove customer or supplier responsibility. A cloud platform can lack a newly exploited platform vulnerability while a customer account, password or access policy is still compromised. Multifactor authentication, network restrictions, credential rotation and monitoring are important controls for those customer environments.
What information was exposed?
What Santander publicly described
Santander confirmed that certain information relating to customers in the three named countries and to employees was accessed. Its public statement did not provide a complete field-by-field inventory.
What the seller alleged
The 30-million, 6-million and 28-million figures came from the reported marketplace advertisement. They should be treated as allegations, not as a confirmed list of stolen fields.
What Santander said was not in the database
Santander said the database did not contain transactional data, online-banking details or passwords that could authorize transactions. That is different from saying the exposed information was harmless. Names, contact details, employment information and other personal data can make phishing, impersonation and identity-fraud attempts more convincing.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsWhich Santander customers should be concerned?
Santander’s identified customer markets were Chile, Spain and Uruguay. The statement did not say that all Santander customers worldwide, or specifically Santander UK customers, were included. Santander said customer data in its other markets and businesses was not affected. People should therefore rely on a direct notice from their own Santander entity rather than infer exposure from the “30 million” headline.
Practical risks for customers
- Targeted emails, texts or calls pretending to be Santander.
- Fraudsters using accurate personal details to appear credible.
- Requests for one-time passcodes, passwords, card details, PINs or security codes.
- Social engineering aimed at customers, employees or their contacts.
- Identity-theft attempts if enough identifying information was exposed.
Santander said it would not ask customers for passwords or one-time codes. A message containing correct personal details can still be fraudulent; accuracy is not authentication.
What to do if you may be affected
- Check through an official channel. Use Santander’s official website, app or telephone number, not a link or number supplied in an unsolicited message.
- Disclose no authentication secrets. Never give a caller or texter your password, one-time passcode, PIN or security code.
- Review activity. Check account transactions, cards and payees for anything unfamiliar.
- Report suspicious activity immediately. Contact Santander through its official channel if you see an unauthorized transaction or suspect account manipulation.
- Replace reused passwords. Change any password shared with another service, beginning with email and other accounts that can reset financial access.
- Turn on multifactor authentication. Use phishing-resistant MFA where a service supports it, and secure your email and password manager first.
- Report phishing. Use Santander’s official reporting process and the relevant national reporting authority.
- Consider monitoring based on your circumstances. Credit or identity monitoring can provide alerts, but it cannot stop a real-time transfer, prevent every phishing attack or guarantee removal of data from criminal markets.
Do not automatically freeze a bank account or replace every card unless Santander instructs you to do so or you have evidence of payment-card exposure.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What happened after disclosure?
Santander said it blocked the compromised access, introduced additional fraud controls, contacted affected customers and employees, and notified regulators and law enforcement. A UK Information Commissioner’s Office disclosure-log entry records a May 23, 2025 request about the investigation, outcome and action involving Santander UK. The entry partially withheld information; it is not a finding that Santander UK was fined or that UK customer data was exposed. See the ICO disclosure log.
Best Value
What remains unknown
- Whether all data advertised in the forum listing was genuine.
- Whether “30 million” represented unique people rather than records or fields.
- Whether a buyer obtained the advertised dataset.
- The complete field-level contents of the accessed database.
- Whether a later regulatory or court finding materially changed the public account.
The sources cited here do not establish a final regulatory penalty, ransom payment or completed sale.
Bottom line
Santander suffered a real unauthorized database access incident, but the strongest headline—30 million Santander customers for sale—came from an unverified criminal-marketplace claim. The confirmed geography was Chile, Spain and Uruguay, plus current and some former employees; Santander said transaction data and transaction-capable credentials were not present. Treat unexpected Santander-themed contact as a phishing risk, verify through official channels and do not confuse a seller’s advertised inventory with an independently confirmed customer count.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




