Breach report
Financial ServicesCapital One
Capital One Data Breach Affects 106 Million People, Suspect Arrested
A former cloud engineer abused a misconfigured firewall to copy credit card application data on 106 million Capital One customers and applicants, then bragged about it online, leading to her arrest and an $80 million regulatory fine.
Reported by BleepingComputer
Records exposed
106M
About 106 million people (100 million U.S., 6 million Canada)
Scale vs. largest on file
- When
- 2019
- How they got in
- Misconfigured web application firewall in cloud environment (server-side request forgery)
- Sector
- Financial Services
On July 29, 2019, Capital One disclosed that an outsider had obtained personal information tied to about 106 million people in the United States and Canada, most of whom had applied for its credit cards between 2005 and early 2019. The same day, the FBI arrested Paige Thompson, a Seattle software engineer who had previously worked at Amazon Web Services, the cloud provider hosting the affected data.
According to court filings, the unauthorized access took place in March 2019. Thompson exploited a misconfigured web application firewall in Capital One's cloud environment, using a technique known as server-side request forgery to obtain credentials that allowed her to list and download data from storage buckets. The bank learned of the theft only after an outside tipster emailed its responsible disclosure address on July 17, pointing to files Thompson had posted on GitHub and comments she had made in online chat groups.
Most of the stolen records came from credit card applications and included names, addresses, phone numbers, email addresses, birth dates and self-reported income. Some records also contained credit scores, limits, balances and fragments of transaction history. About 140,000 U.S. Social Security numbers, roughly 80,000 linked bank account numbers and around 1 million Canadian Social Insurance Numbers were exposed. Capital One said it found no evidence the data had been sold or used for fraud.
The bank estimated initial costs of $100 million to $150 million in 2019 for notification, credit monitoring, technology and legal work. In August 2020, the Office of the Comptroller of the Currency fined Capital One $80 million for failing to identify and manage risks before moving operations to the cloud. The company later agreed to a $190 million class-action settlement with affected customers. A federal jury convicted Thompson of wire fraud and computer intrusion charges in June 2022, and she was sentenced to time served plus five years of probation.
The case became a textbook example of cloud security risk. The flaw was not in Amazon's platform itself but in how the customer configured it, illustrating the shared-responsibility model in which a provider secures its infrastructure while clients must lock down their own settings. It also showed that large institutions can miss an intrusion for months until an outsider notices the evidence.