Capital One 2019: one cloud firewall mistake, 106 million people and one tip
For almost 4 months in 2019, data on about 106 million Capital One customers and applicants sat on a stranger's server, and the bank learned about it from an email to its bug-report inbox.[1][2] This long read follows the case from the scanning tool to the firewall setting, the online boasting, the arrest, a sentence that split the courts, and the control that would have caught it in March instead of July.
The engineer and the scanning tool
Paige Thompson was a Seattle software engineer who had worked at Amazon Web Services, the cloud platform on which Capital One ran a large part of its business.[5][2] By 2019 she was building a tool of her own. According to the Justice Department, it scanned the internet for cloud accounts that had been set up wrong, and she used the mistakes it found to get inside.[3]
The tool found plenty. Prosecutors said she reached data belonging to more than 30 organizations. On some of those servers she installed cryptocurrency-mining software, so that other companies' paid computing power earned coins for her own wallet.[3] One of the organizations on her list was a major US bank.
The weakness she hunted for was not exotic. A web application firewall is a filter placed in front of a website to block malicious traffic. Set up carelessly, it can be tricked into making requests on an outsider's behalf from inside the network, a class of flaw known as server-side request forgery.[4] Inside a cloud network, one internal address hands out temporary credentials to any server that asks for them. A tricked firewall can ask on the attacker's behalf.[4]
In other words, the attack did not start with Capital One. It started with a general search for a common configuration mistake, and Capital One happened to have it.
The firewall setting that exposed 106 million records
On March 22 and 23, 2019, someone used Capital One's misconfigured firewall to reach its cloud storage.[1][2] The credentials the firewall handed over belonged to a server role, a cloud identity that defines what a machine may do. That role carried far more permission than a firewall needs: it could list the bank's storage buckets and read what was in them.[4]
What came out was years of credit card application data, from 2005 to early 2019. It included names, addresses, phone numbers, email addresses, dates of birth and self-reported income, plus credit scores, limits, balances and payment history for some customers, and fragments of transaction data from 23 days between 2016 and 2018.[1] It also included about 140,000 US Social Security numbers, about 80,000 linked bank account numbers and about 1 million Canadian Social Insurance Numbers. In total, about 100 million people in the US and 6 million in Canada were affected.[1]
Capital One said no credit card account numbers or login credentials were taken.[1] Still, nothing inside the bank raised an alarm while a firewall's identity read through its customer files. The data went to a server outside the bank and stayed there, untouched by any detection, for months.[1][2]
The online boasting and the tip that ended it
She did not sell the data. She talked about it. Prosecutors said she bragged about her intrusions to others by text and in online forums.[3] She used the handle erratic, and she posted material about the theft on GitHub, a public site for sharing code.[2] Krebs on Security reported that the data she posted there had been encrypted first.[4]
Someone who saw those posts did the responsible thing. On July 17, 2019, a message arrived through Capital One's Responsible Disclosure Program, the channel the bank ran for outsiders to report security problems. The tipster pointed to the GitHub material and suggested the bank may have suffered a data theft.[1][2]
Two days later, on July 19, Capital One confirmed the intrusion and contacted the FBI.[1][2] Four months of silence inside the bank ended within 48 hours of an outsider's email.
The arrest, the fines and the settlement
On July 29, 2019, FBI agents searched Thompson's Seattle home, seized storage devices holding a copy of the data, and arrested her. She was 33 and charged with computer fraud and abuse.[2] The government later said it believed the data had been recovered and that there was no evidence it was used for fraud or shared.[1]
The bank's regulator, the Office of the Comptroller of the Currency, fined Capital One $80 million in 2020 over its data protection failures.[5][6] The bank also agreed to a $190 million class-action settlement with affected customers.[5] Together, penalties and settlement came to $270 million, before counting the cost of the response itself.
The criminal case took 3 years to reach trial. On June 17, 2022, after a 7-day trial and about 10 hours of deliberation, a Seattle jury convicted her of wire fraud, 5 counts of unauthorized access to a protected computer and 1 count of damaging a protected computer. It acquitted her of access device fraud and aggravated identity theft.[3] At trial, a prosecutor summed up the government's view: she wanted data, money and bragging rights.[3]
A sentence that split the courts
Prosecutors asked for 7 years in prison. In early October 2022, US District Judge Robert Lasnik sentenced her to time served plus 5 years of probation with location and computer monitoring.[5][6] He pointed to her mental health and said prison would be particularly hard on her as a transgender woman.[5][6] The US Attorney in Seattle responded publicly that this was not what justice looks like.[5]
The government appealed, and the Ninth Circuit Court of Appeals vacated the sentence as too lenient and sent it back.[7] Federal sentencing guidelines had called for 135 to 168 months, and at resentencing prosecutors asked for 84 months.[7]
In November 2025 the same judge reached the same conclusion. He imposed time served, 5 years of supervised release including 3 years of home confinement, and 250 hours of community service, and kept restitution at $40.7 million. He wrote that he could not find prison would deliver needed medical care or treatment in the most effective way.[7]
Why the bank found out from a stranger
Put the chain back together. The bank learned of the breach from an outside tip because nothing internal flagged a firewall's credentials reading large amounts of customer data.[1][2] The data was readable because the firewall's server role had permission to list and read storage it never needed.[4] And the credentials were reachable because the firewall was misconfigured in a way that let an outsider make it ask for them.[2][4]
Break any one of those links and the case shrinks: a configuration review catches the firewall, a tighter role limits what the credentials open, or an alert on bulk reads cuts 4 months down to hours.
Timeline
| Date | What happened |
|---|---|
| Mar 22–23, 2019 | Data copied from Capital One's cloud storage.[1] |
| Jul 17, 2019 | Tip arrives through the bank's responsible disclosure program.[1][2] |
| Jul 19, 2019 | Capital One confirms the intrusion and contacts the FBI.[1][2] |
| Jul 29, 2019 | FBI searches Thompson's home and arrests her in Seattle.[2] |
| 2020 | OCC fines Capital One $80 million.[6] |
| 2022 | $190 million class settlement with customers.[1][5] |
| Jun 17, 2022 | Jury convicts Thompson on 7 counts, acquits on 2.[3] |
| Oct 2022 | Sentenced to time served and 5 years of probation.[5][6] |
| 2025 | Ninth Circuit vacates the sentence as too lenient.[7] |
| Nov 2025 | Resentenced to time served, home confinement and $40.7 million restitution.[7] |
The missing control
The missing control: reviewing cloud settings and permissions before and after they go live, with each machine's access limited to what it needs and an alert on bulk reads of customer data.
- Inventory your cloud services. List every cloud account, storage service and app your business pays for or connects to. Forgotten accounts are the ones nobody reviews.
- Trim what each account can reach. For every staff login, shared folder, app connection and server, ask what it actually needs to read. Remove everything else, starting with anything that can see customer data.
- Run the built-in security check monthly. Most business cloud platforms include a configuration or sharing report. Read it, or have your IT provider summarize it, and fix what it flags.
- Turn on alerts for mass downloads. Ask for a notice when an account downloads or syncs an unusual volume of files. A large overnight pull of customer records should reach a person within hours.
- Give outsiders a way to warn you. Publish a security contact on your website and make sure someone reads it. That inbox is how Capital One found out.
What it means now
Capital One was not careless about security in general, and it was not the only organization hit by the same scanner. What it shows is that in the cloud, a single setting and an overly generous permission can matter as much as any hacker's skill, and that logs nobody watches are not a defense.
Small businesses now run on the same kind of rented cloud services. The habits that would have shortened this case, knowing what you have, limiting who and what can read it, and getting alerted when something reads too much, cost little and work at any size.
How the Capital One breach happened: one misconfigured cloud firewall: the case file and the Shorts from this case.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- What caused the Equifax breach? An unpatched website and an expired certificate
- What happened to Knight Capital: $460 million lost in 45 minutes
- How WannaCry hit the NHS: the fix existed 2 months before the attack
- How the Heartland breach happened: 130 million cards and an informant
- How the HSE cyber attack happened: one spreadsheet and 8 weeks of ignored alerts
- All episodes
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Capital One: Information on the Capital One cyber incident
- US Department of Justice (W.D. Wash.): Seattle tech worker arrested for data theft involving large financial services company
- US Department of Justice (W.D. Wash.): Former Seattle tech worker convicted of wire fraud and computer intrusions
- Krebs on Security: What we can learn from the Capital One hack
- CBS News: Seattle software engineer gets probation for 2019 Capital One hack
- The Register: DOJ unhappy with Capital One hacker's sentence
- CyberScoop: Court reimposes original sentence for Capital One hacker