Case file · CAPITAL ONE 2019

How the Capital One breach happened: one misconfigured cloud firewall

Published 2026-09-26 · 4 min read

The person who copied data on about 106 million Capital One customers and applicants was not caught by an alarm inside the bank. She was caught because she talked about it, and a stranger emailed the bank a tip.[1][2] This case file covers how a single cloud setting opened the door, what the fallout cost, and the one habit that would have closed it sooner.

What happened

On March 22 and 23, 2019, an outsider reached into Capital One's cloud environment and copied files holding years of credit card application data.[1] The haul covered roughly 100 million people in the US and about 6 million in Canada. Most of it was names, addresses, dates of birth, self-reported income, credit scores and payment history, but it also included about 140,000 US Social Security numbers, about 80,000 linked bank account numbers and about 1 million Canadian Social Insurance Numbers.[1]

For almost four months, nobody at the bank noticed. Then, on July 17, 2019, a message arrived through Capital One's responsible-disclosure program, the public inbox where outsiders can report security problems. The tipster had spotted Capital One files posted on a public code-sharing site.[1][3] The bank confirmed the intrusion on July 19 and alerted the FBI.[1][2]

The perpetrator, Paige Thompson, a former Amazon Web Services employee living in Seattle, was arrested in July 2019.[2][7] Prosecutors later showed she had hit more than 30 organizations the same way, and in some cases planted cryptocurrency-mining software on the servers she reached, sending the proceeds to her own wallet.[2] She had bragged about the intrusions in texts and online forum posts.[2]

How they got in

Capital One ran part of its business on rented cloud servers. In front of one application sat a web application firewall, a filter meant to block bad web traffic before it reaches the systems behind it. That firewall was misconfigured.[1][3]

According to post-incident reporting, the flaw let an outsider trick the firewall's server into handing over the temporary login credentials the cloud gives its own machines. Those credentials carried far more permission than the firewall needed: they could list and read files in the bank's cloud storage, including the ones holding customer data.[3] So the door was not broken. A guard was fooled into lending out a master key, and the key opened rooms the guard had no business entering.

The Justice Department described the pattern plainly: she scanned for cloud accounts that had been set up wrong, then used those mistakes to download data.[2]

How it was caught and what it cost

Detection came from outside, not from Capital One's own monitoring. On August 6, 2020, the Office of the Comptroller of the Currency (OCC), which supervises national banks, fined Capital One $80 million. It said the bank had failed to assess risk properly before moving to the public cloud, had weak network security and data-loss controls in that environment, and lacked effective alerting, and that internal audit had not flagged the gaps to the board.[4]

Capital One agreed to a $190 million class-action settlement, which received final court approval on September 13, 2022; payments went out in 2023 and 2024.[5][8]

In court, a federal jury in Seattle convicted Thompson on June 17, 2022, of wire fraud, five counts of unauthorized access to a protected computer, and damaging a protected computer. The jury acquitted her of access device fraud and aggravated identity theft.[2] Prosecutors asked for 7 years in prison. In October 2022, US District Judge Robert Lasnik instead sentenced her to time served plus 5 years of probation, citing her mental health and other personal circumstances.[5] The US Attorney's response was blunt: "This is not what justice looks like."[5]

In March 2025, a divided federal appeals court called the sentence substantially unreasonable and sent it back.[6] In November 2025, the same judge imposed the same sentence again: time served, 5 years of supervised release including 3 years of home confinement, 250 hours of community service, and $40.7 million in restitution.[7]

The missing control

The missing control: continuous review of cloud configurations and permissions, paired with alerts on unusual data access.

Two things had to be true for this breach to work. A security filter had to be set up wrong, and the credentials behind it had to be allowed to read far more than they should. Routine, automated checks of cloud settings are built to catch exactly that kind of drift: a component with permissions it does not need, or a rule that lets the wrong requests through. Either finding, fixed in time, shrinks this case to a non-event.

The second half matters just as much. A firewall's credentials suddenly listing and reading large volumes of customer files is not normal behavior. An alert on that pattern would have fired in March, not waited for a stranger's email in July. The OCC's own findings pointed at both gaps: weak data-loss controls and a lack of effective alerting.[4]

What to do in your business

Watch the case
Episode drops 2026-10-02
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More case files

Facts are drawn from court records, government reports and reputable reporting, listed below. People are named only where they were convicted or spoke publicly in an official role.

Sources
  1. Capital One: Information on the Capital One cyber incident
  2. US Department of Justice (W.D. Wash.): Former Seattle tech worker convicted of wire fraud and computer intrusions
  3. Krebs on Security: What we can learn from the Capital One hack
  4. Willkie Compliance Concourse: OCC fines Capital One $80 million for cloud security violations related to cyber breach
  5. CBS News: Seattle software engineer gets probation for 2019 Capital One hack
  6. CyberScoop: Capital One hacker Paige Thompson got too light a sentence, appeals court rules
  7. CyberScoop: Court reimposes original sentence for Capital One hacker
  8. Capital One Data Breach Settlement: Official settlement website