Back to the archive

The encyclopedia · Software & IT · Operational decision · 2019

A former AWS engineer stole 100M Capital One records via a misconfigured firewall

In 2019, a former AWS engineer exploited a misconfigured firewall to steal 100M Capital One customers' data. It was the largest bank breach in history.

Capital One · Amazon Web Services · 2019-07

What happened

In July 2019, Capital One disclosed that a hacker had accessed the personal data of approximately 100 million customers and applicants — one of the largest data breaches in banking history. The stolen data included names, addresses, credit scores, income information and some Social Security numbers.

The hacker, Paige Thompson, a former AWS engineer, exploited a misconfigured web application firewall (WAF) in Capital One's cloud infrastructure on Amazon Web Services. The misconfiguration allowed Thompson to access internal data stored in AWS cloud storage buckets.

Capital One was fined $80 million by the Office of the Comptroller of the Currency for failing to establish effective risk management. Thompson was arrested and convicted. The case illustrated how cloud migration introduces new security risks that traditional bank security teams may not be equipped to manage, and how a single misconfiguration in a cloud environment can expose data at a scale that on-premises systems would not allow.

Why it happened

  • A misconfigured web application firewall allowed a former AWS engineer to access internal data.
  • 100M customers' personal data was stolen, including credit scores and SSNs.
  • Capital One's security team did not detect the breach for several months.
  • Capital One was fined $80M for inadequate risk management.
What it cost100M customers affected; $80M fine; largest bank breachcostly

The lesson

Cloud migration is a security model change, not just a technology change. Capital One's team managed a cloud they didn't fully understand. The cloud makes the consequences of failure larger.

Aftermath

Capital One was fined $80M and overhauled its cloud security practices. Thompson was convicted and sentenced. The case prompted financial regulators to issue guidance on cloud security risk management for banks.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →