US bank Capital One disclosed that an attacker had accessed personal data on around 106 million people in the United States and Canada. A former cloud engineer, Paige Thompson, was arrested by the FBI the same day.
What happened
- The data came mainly from credit card applications and included names, addresses, dates of birth, and credit scores.
- Around 140,000 US Social Security numbers, 80,000 bank account numbers, and about one million Canadian Social Insurance Numbers were affected.
- The attacker exploited a misconfigured web application firewall to access data stored in the bank’s cloud environment.
- Thompson was convicted in 2022 of wire fraud and computer intrusion offences.
Why it mattered
The breach became a textbook case of cloud misconfiguration and led to an $80 million penalty from the US Office of the Comptroller of the Currency. It also raised questions about shared responsibility between cloud providers and their customers, since the weakness lay in how the bank had configured its own environment.
Lessons for organisations
Review cloud configurations regularly, apply least privilege to cloud roles and metadata services, and use continuous monitoring to spot unusual data access.
Sources: BleepingComputer, Krebs on Security
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.