← LendingTree

2024 LendingTree QuoteWizard — 190M (Snowflake)

2024 190.0M records affected Share on X

Data compromised

Customer details, partial credit card numbers, insurance quotes

Technical writeup

LendingTree's subsidiary QuoteWizard was compromised in the June 2024 Snowflake breach campaign. UNC5537 threat actors used stolen credentials to access QuoteWizard's Snowflake instance. Data on over 190 million people was offered for sale on cybercriminal forums, including customer details, partial credit card numbers, and insurance quotes. Parent company LendingTree stated consumer financial accounts were not impacted.

Root cause

Snowflake credential compromise; UNC5537 campaign; stolen credentials from infostealer malware

References