2024 LendingTree QuoteWizard — 190M (Snowflake)
Data compromised
Customer details, partial credit card numbers, insurance quotes
Technical writeup
LendingTree's subsidiary QuoteWizard was compromised in the June 2024 Snowflake breach campaign. UNC5537 threat actors used stolen credentials to access QuoteWizard's Snowflake instance. Data on over 190 million people was offered for sale on cybercriminal forums, including customer details, partial credit card numbers, and insurance quotes. Parent company LendingTree stated consumer financial accounts were not impacted.
Root cause
Snowflake credential compromise; UNC5537 campaign; stolen credentials from infostealer malware