How the Capital One breach happened: one misconfigured cloud firewall
The person who copied data on about 106 million Capital One customers and applicants was not caught by an alarm inside the bank. She was caught because she talked about it, and a stranger emailed the bank a tip.[1][2] This case file covers how a single cloud setting opened the door, what the fallout cost, and the one habit that would have closed it sooner.
What happened
On March 22 and 23, 2019, an outsider reached into Capital One's cloud environment and copied files holding years of credit card application data.[1] The haul covered roughly 100 million people in the US and about 6 million in Canada. Most of it was names, addresses, dates of birth, self-reported income, credit scores and payment history, but it also included about 140,000 US Social Security numbers, about 80,000 linked bank account numbers and about 1 million Canadian Social Insurance Numbers.[1]
For almost four months, nobody at the bank noticed. Then, on July 17, 2019, a message arrived through Capital One's responsible-disclosure program, the public inbox where outsiders can report security problems. The tipster had spotted Capital One files posted on a public code-sharing site.[1][3] The bank confirmed the intrusion on July 19 and alerted the FBI.[1][2]
The perpetrator, Paige Thompson, a former Amazon Web Services employee living in Seattle, was arrested in July 2019.[2][7] Prosecutors later showed she had hit more than 30 organizations the same way, and in some cases planted cryptocurrency-mining software on the servers she reached, sending the proceeds to her own wallet.[2] She had bragged about the intrusions in texts and online forum posts.[2]
How they got in
Capital One ran part of its business on rented cloud servers. In front of one application sat a web application firewall, a filter meant to block bad web traffic before it reaches the systems behind it. That firewall was misconfigured.[1][3]
According to post-incident reporting, the flaw let an outsider trick the firewall's server into handing over the temporary login credentials the cloud gives its own machines. Those credentials carried far more permission than the firewall needed: they could list and read files in the bank's cloud storage, including the ones holding customer data.[3] So the door was not broken. A guard was fooled into lending out a master key, and the key opened rooms the guard had no business entering.
The Justice Department described the pattern plainly: she scanned for cloud accounts that had been set up wrong, then used those mistakes to download data.[2]
How it was caught and what it cost
Detection came from outside, not from Capital One's own monitoring. On August 6, 2020, the Office of the Comptroller of the Currency (OCC), which supervises national banks, fined Capital One $80 million. It said the bank had failed to assess risk properly before moving to the public cloud, had weak network security and data-loss controls in that environment, and lacked effective alerting, and that internal audit had not flagged the gaps to the board.[4]
Capital One agreed to a $190 million class-action settlement, which received final court approval on September 13, 2022; payments went out in 2023 and 2024.[5][8]
In court, a federal jury in Seattle convicted Thompson on June 17, 2022, of wire fraud, five counts of unauthorized access to a protected computer, and damaging a protected computer. The jury acquitted her of access device fraud and aggravated identity theft.[2] Prosecutors asked for 7 years in prison. In October 2022, US District Judge Robert Lasnik instead sentenced her to time served plus 5 years of probation, citing her mental health and other personal circumstances.[5] The US Attorney's response was blunt: "This is not what justice looks like."[5]
In March 2025, a divided federal appeals court called the sentence substantially unreasonable and sent it back.[6] In November 2025, the same judge imposed the same sentence again: time served, 5 years of supervised release including 3 years of home confinement, 250 hours of community service, and $40.7 million in restitution.[7]
The missing control
The missing control: continuous review of cloud configurations and permissions, paired with alerts on unusual data access.
Two things had to be true for this breach to work. A security filter had to be set up wrong, and the credentials behind it had to be allowed to read far more than they should. Routine, automated checks of cloud settings are built to catch exactly that kind of drift: a component with permissions it does not need, or a rule that lets the wrong requests through. Either finding, fixed in time, shrinks this case to a non-event.
The second half matters just as much. A firewall's credentials suddenly listing and reading large volumes of customer files is not normal behavior. An alert on that pattern would have fired in March, not waited for a stranger's email in July. The OCC's own findings pointed at both gaps: weak data-loss controls and a lack of effective alerting.[4]
What to do in your business
- List every cloud account you pay for. You cannot review settings on a service you forgot you had.
- Check who and what can read your files. Look for folders shared by public link, former staff who still have access, and connected apps with broad permissions you no longer need. Remove what is not in use.
- Turn on the built-in security review. Most business cloud services include a security or sharing report. Schedule 15 minutes a month to read it, or ask your IT provider to send you a summary.
- Switch on alerts for mass downloads and new logins. Many services can email you when a large number of files are downloaded or an account signs in from somewhere new. A late-night bulk download should never be a surprise you learn about months later.
- Publish a way for outsiders to warn you. A simple security contact on your website, checked by a real person, is how Capital One finally found out. Make sure a tip reaches someone who will act on it.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- What caused the Equifax breach? An unpatched website and an expired certificate
Facts are drawn from court records, government reports and reputable reporting, listed below. People are named only where they were convicted or spoke publicly in an official role.
- Capital One: Information on the Capital One cyber incident
- US Department of Justice (W.D. Wash.): Former Seattle tech worker convicted of wire fraud and computer intrusions
- Krebs on Security: What we can learn from the Capital One hack
- Willkie Compliance Concourse: OCC fines Capital One $80 million for cloud security violations related to cyber breach
- CBS News: Seattle software engineer gets probation for 2019 Capital One hack
- CyberScoop: Capital One hacker Paige Thompson got too light a sentence, appeals court rules
- CyberScoop: Court reimposes original sentence for Capital One hacker
- Capital One Data Breach Settlement: Official settlement website