Over 100 million U.S. citizens and six million Canadian residents had data from Capital One stolen and a suspected hacker is under arrest.

If a person applied for a credit card from the U.S. bank between 2005 through 2019, your information is likely part of this breach, Capital One said in a statement. The data includes 140,000 U.S. Social Security numbers and about 80,000 bank account numbers, according to Capital One. The hacker also stole about 1 million Canadian social insurance numbers in the breach.

“No credit card account numbers or log-in credentials were compromised” and that more than 99 percent of the Social Security numbers that Capital One has on file weren’t affected, Capitol One said.

The breach did, however, include names, addresses, ZIP codes, phone numbers, email addresses and birthdates — all valuable assets hackers can use to steal from victims.

Schneider Bold

The FBI arrested a 33-year-old tech worker named Paige A. Thompson, who goes by the nickname “erratic,” according to the Justice Department (DoJ). Prosecutors charged Thompson with computer fraud and abuse, alleging that she was behind the hack. Computer fraud and abuse is punishable by up to five years in prison and a $250,000 fine if found guilty.

Thompson posted on the information sharing site GitHub about her theft of information from the servers storing Capital One data, according to DoJ. The intrusion occurred through a misconfigured web application firewall that enabled access to the data. On July 17, a GitHub user who saw the post alerted Capital One to the possibility it had suffered a data theft. After determining on July 19 there had been an intrusion into its data, Capital One contacted the FBI. Cyber investigators were able to identify Thompson as the person who was posting about the data theft.

Search Warrant Executed
On Monday, agents executed a search warrant at Thompson’s home and seized electronic storage devices containing a copy of the data.

“While I am grateful that the perpetrator has been caught, I am deeply sorry for what has happened,” said Richard D. Fairbank, chairman and CEO of Capital One. “I sincerely apologize for the understandable worry this incident must be causing those affected and I am committed to making it right.”

This misconfigured firewall was on Capital One’s cloud server, officials said. Investigators accused Thompson of accessing that server from March 12 to July 17. More than 700 folders of data were stored on that server, according to the Justice Department.

Thompson allegedly posted details about the hack on a GitHub page in April, and talked about the attack on Twitter and Slack discussions, according to the FBI.

The GitHub page had Thompson’s full name, as well as another page containing her resume. Court documents showed that on the resume, Thompson was listed as a systems engineer and was an employee at Amazon Web Services from 2015 to 2016. In a statement, Amazon said the former employee left the company three years before the hack took place.

Amazon said AWS wasn’t compromised in anyway, pointing out that the alleged hacker gained access through a misconfiguration on the cloud server’s application, not through a vulnerability in its infrastructure.

Industry Comment
“The Capital One breach is a classic example of the ‘insider threat’ which has been present since the first merchant hung a shingle and sold goods and is certainly not limited to the digital age,” said Michael Magrath, director of global regulations and standards at OneSpan. “The insider threat is not limited to employees and extends to third party providers as Capital One fell victim to. The third-party provider threat is a concern for CISO’s and regulators alike, which is why the New York Department of Financial Services’ Cybersecurity Requirements for Financial Services Companies (23 NYCRR 500) include specific requirements regarding third-party service providers.”

“An interesting aspect to consider in this breach is that Capital One also serves as a supplier for businesses,” said Giora Omer, head of security architecture at Panorays. “It has an outstanding security team and the highest standards and methodologies in cybersecurity, particularly in the cloud. Therefore, this breach illustrates how every company is vulnerable – it could be a large, small, critical or low risk supplier.”

ISSSource

Pin It on Pinterest

Share This