Recommended Free Tools
Santander confirmed unauthorized access to a database hosted by a third-party provider in May 2024, but it did not confirm ShinyHunters’ reported claim that data for around 30 million customers was involved. That figure, and the group’s description of the data, were reported by ITPro as claims by ShinyHunters—not as an independently verified count.
What Santander confirmed about the breach
In a statement dated 14 May 2024, Banco Santander said it had become aware of unauthorized access to a Santander database hosted by a third-party provider. The bank said it contained the compromised access and put additional fraud-prevention controls in place. Santander’s statement
Santander said information relating to customers in Chile, Spain and Uruguay had been accessed, along with information about all current and some former Santander group employees. It said customer data in its other markets and businesses was not affected. The statement did not give a total number of affected customers.
Where the “30 million customers” figure comes from
ITPro reported on 7 August 2025 that ShinyHunters claimed responsibility for the May 2024 incident. According to that report, the group said it had data for around 30 million customers, including financial data and credit-card details, and listed the data for sale. Those are the group’s claims as relayed by ITPro; Santander’s public statement does not confirm the claimed dataset size or every type of data described. ITPro’s report
#1 Best Overall
So, did ShinyHunters really steal data from 30 million Santander customers? The available statements establish that the group made that claim and that Santander confirmed unauthorized database access. They do not independently verify that 30 million individual customers were affected.
What Santander said the database did not contain
Santander said the database did not contain transaction data or credentials that would enable transactions, including online banking details and passwords. In the bank’s words: “No transactional data, nor any credentials that would allow transactions to take place on accounts are contained in the database, including online banking details and passwords.”
The bank also said its operations and systems were not affected and that customers could continue to transact. These are Santander’s statements about the incident, not a separately established forensic conclusion in the sources cited here.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What customers should do
Santander said it was proactively contacting affected customers and employees and had notified regulators and law enforcement. Its guidance to customers was to:
- Never provide passwords or security codes in response to a message or caller.
- Check information using the bank’s official channels rather than replying to an unsolicited message.
- Report suspicious messages directly to the bank.
- Avoid links in suspicious or unsolicited emails when accessing online banking; use the bank’s official app or enter its address yourself.
The incident concerns unauthorized access to a database, not confirmation that customer accounts were taken over. Santander’s statement said the database lacked credentials that would permit transactions; customers should still treat unexpected requests for codes, passwords or banking details with caution.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




