Capital One announces massive data breach; lone suspect arrested in Seattle
Full article847 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The breach affected approximately 100 million individuals in the United States and approximately 6 million in Canada.
Financial giant Capital One announced a large data breach Monday, with the company saying that one person accessed personal information of approximately 100 million people in the United States and 6 million in Canada who had applied for or are currently considered users of the company’s credit cards.
Additionally, the FBI arrested a woman in Washington state who is suspected of hacking into the company to obtain that information. Paige A. Thompson was arrested Monday and appeared in federal court in Seattle.
According to the complaint, Thompson allegedly took wide swaths of personal information from Capital One’s cloud storage instances on March 22 and March 23. The company stored the data taken by Thompson on Amazon Web Services.
The company says this information included names, addresses, zip codes/postal codes, phone numbers, email addresses, dates of birth and self-reported income. The information ranged from 2005 to early 2019.
Additionally, Capital One says the following information was obtained:
- Customer status data such as credit scores, credit limits, balances, payment history and contact information.
- Fragments of transaction data from a total of 23 days during 2016, 2017 and 2018.
- About 140,000 Social Security numbers of credit card customers.
- About 80,000 linked bank account numbers of secured credit card customers.
- Approximately 1 million Canadian Social Insurance Numbers.
According to the FBI, a misconfigured firewall allowed Thompson to access a list of more than 700 folders that contained the data. Sometime shortly thereafter, Thompson allegedly posted on GitHub that she was in possession of the data.
The company was made aware of the breach on July 17 when someone emailed Capital One via their security disclosure email contact and informed it the data was publicly posted on GitHub.
“While I am grateful that the perpetrator has been caught, I am deeply sorry for what has happened,” said Richard D. Fairbank, Capital One chairman and CEO, said in a press release. “I sincerely apologize for the understandable worry this incident must be causing those affected and I am committed to making it right.”
The company says it will be make free credit monitoring and identity protection available to everyone affected.
In a press release issued Monday, Capital One said it expects the incident to cost the company between $100 million and $150 million this year. It also stated it has a cyber insurance package with a total coverage limit of $400 million.
Thompson was a former employee of Amazon Web Services from 2015 to 2016, according to her LinkedIn profile. If convicted, she faces a five-year prison sentence and a fine up to $250,000.
You can read the full complaint below.
[documentcloud url=”http://www.documentcloud.org/documents/6224650-Paige-Thompson-complaint.html” responsive=true]
More Scoops
CISA credential leak raises alarms, and Capitol Hill demands answers
A researcher who found a repository that leaked on GitHub said it was one of the worst he’s witnessed.
Court reimposes original sentence for Capital One hacker
Capital One hacker Paige Thompson got too light a sentence, appeals court rules
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/capital-one-data-breach-credit-cards/