The encyclopedia · Software & IT · Operational decision · 2019
A former AWS engineer stole 100M Capital One records via a misconfigured firewall
In 2019, a former AWS engineer exploited a misconfigured firewall to steal 100M Capital One customers' data. It was the largest bank breach in history.
Capital One · Amazon Web Services · 2019-07
What happened
In July 2019, Capital One disclosed that a hacker had accessed the personal data of approximately 100 million customers and applicants — one of the largest data breaches in banking history. The stolen data included names, addresses, credit scores, income information and some Social Security numbers.
The hacker, Paige Thompson, a former AWS engineer, exploited a misconfigured web application firewall (WAF) in Capital One's cloud infrastructure on Amazon Web Services. The misconfiguration allowed Thompson to access internal data stored in AWS cloud storage buckets.
Capital One was fined $80 million by the Office of the Comptroller of the Currency for failing to establish effective risk management. Thompson was arrested and convicted. The case illustrated how cloud migration introduces new security risks that traditional bank security teams may not be equipped to manage, and how a single misconfiguration in a cloud environment can expose data at a scale that on-premises systems would not allow.
Why it happened
- A misconfigured web application firewall allowed a former AWS engineer to access internal data.
- 100M customers' personal data was stolen, including credit scores and SSNs.
- Capital One's security team did not detect the breach for several months.
- Capital One was fined $80M for inadequate risk management.
The lesson
Cloud migration is a security model change, not just a technology change. Capital One's team managed a cloud they didn't fully understand. The cloud makes the consequences of failure larger.
Aftermath
Capital One was fined $80M and overhauled its cloud security practices. Thompson was convicted and sentenced. The case prompted financial regulators to issue guidance on cloud security risk management for banks.
Sources
- 2019 Capital One data breach — Wikipedia
- Capital One data breach: 100 million records stolen — BBC News (Jul 2019)
spotted an error? The club wants to know.
More like this
Allianz Life's CRM vendor door exposed most of its 1.4M customers
Allianz Life exposed most of 1.4M customers through a third-party CRM
Equifax left a known software flaw unpatched — and exposed the data of 147 million people
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.