Desk live·
ForensicPost
Breaches/Finance/File 24-0514

Santander Customer Data Listed for Sale After Third-Party Access

Santander said a database hosted by a third-party provider had been accessed, affecting customers in Spain, Chile and Uruguay and all current and some former staff. A seller then advertised 30 million records.

Constructed geometry · not a chart of case data
JurisdictionSpainMadridthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSantander
ActorUnattributed
S. Rosler8 min readConfidence: medium1 source reviewed

Santander disclosed in May 2024 that a database hosted by a third-party provider had been accessed without authorisation. The bank said the affected population covered customers in Spain, Chile and Uruguay, along with all current and some former employees. It stated that no transactional data or online banking credentials were held in the affected database.

A seller subsequently advertised what was described as 30 million customer records on a criminal forum. The incident is one of those later linked to the campaign against Snowflake customer environments filed at 24-0602.

The Bank Was Not Breached

The database sat with a provider. Santander’s own banking systems were not the point of entry, and the bank was accurate to say so.

For a customer in Santiago or Montevideo the distinction is procedural. Their data left through an arrangement they were never told about, and the notification arrives from the bank because the bank is the only party they have ever dealt with.

Employees Had No Choice At All

All current staff were affected. A customer can at least change bank; an employee handed over their details as a condition of employment.

Graded medium: the 30 million figure comes from the party selling the data, and the bank has not published a count of its own.

How we reported this

Compiled from the bank’s statements and public reporting, listed below. The 30 million figure is the seller’s and is not corroborated by Santander. The third-party provider was not named in the bank’s disclosure. Corrections: corrections@forensicpost.com.

Sources
  1. Santander data breach exposes info of customers and employeesBleepingComputer
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary