01Summary
In July 2019, Paige Thompson, a former Amazon Web Services engineer, exploited a misconfigured firewall rule within Capital One's AWS environment. This vulnerability allowed her to bypass security controls and access databases containing highly sensitive customer information. The breach exposed data from over 100 million people in the US and 6 million in Canada. The stolen data included names, addresses, SSNs, and financial details from credit applications dating back to 2005. Thompson publicized her actions on platforms like GitHub and Slack, leading to her subsequent arrest by federal authorities. The incident served as a major case study in the 'Shared Responsibility Model' of cloud computing, demonstrating that even with secure infrastructure (AWS), client-side misconfiguration can lead to catastrophic data loss.
02Background
The incident occurred in the context of increasing reliance on cloud computing services, where organizations like Capital One utilize major providers such as Amazon Web Services (AWS). This reliance necessitates strict adherence to security best practices, making misconfiguration a persistent and high-risk threat vector.
03Key revelations
- 01The failure of the 'Shared Responsibility Model' implementation by the client (Capital One).
- 02The exposure of highly sensitive PII, including SSNs and financial data, from decades of credit applications.
- 03The public demonstration of a critical cloud security flaw, leading to immediate regulatory scrutiny.
04Technical analysis
The core vulnerability was a misconfigured AWS firewall (Security Group). This misconfiguration allowed Thompson to bypass the intended network segmentation and access data stored in S3 buckets and databases that should have been restricted. The attack vector was not a zero-day exploit, but rather a failure in the implementation of the principle of least privilege and network access control.
- Attack vector
- Misconfigured AWS Firewall/Security Group
- Attack method
- Unauthorized Data Access and Exfiltration
- Initial access
- Misconfigured Cloud Firewall
- Lateral movement
- Internal Network Access via Misconfiguration
- Exfiltration
- Direct Data Download/Exfiltration
- Malware type
- Data Exfiltration
Vulnerabilities exploited
- AWS Misconfiguration (Security Group Rule Failure)
MITRE ATT&CK techniques
- T1046
- T1537
05Threat actor
Paige Thompson was an individual hacker who gained notoriety for exploiting a major financial institution's cloud misconfiguration. Her actions were primarily motivated by demonstrating a vulnerability rather than financial gain, leading to her public arrest.
Aliases
- erratic
MITRE groups
- T1190
Known members
- Paige Thompson
Attribution sources
- FBI
- AWS
- Media Reports
06Victims and impact
Countries affected
- United States
- Canada
07Data exposed
Data types
- Names
- Addresses
- Zip Codes
- Phone Numbers
- Social Security Numbers
- Financial Records
- Credit Application Data
Notable documents
- Credit Application Database Records (2005-2019)
08Financial damage
Damage estimate is complex, involving regulatory fines, remediation costs, and potential class-action lawsuits.
09Timeline
- 2019-07-19Initial unauthorized access to Capital One data via misconfigured AWS firewall.
- 2019-07-29Breach publicly disclosed, leading to the arrest of Paige Thompson.
10Key figures
- Paige ThompsonHacker/Perpetrator · Former AWS EngineerAmericanArrested and charged by federal authorities.
11On the record
The breach exposed the personal information of over 100 million people in the US and 6 million in Canada.
12Reaction and fallout
Public reaction
The public reaction was characterized by alarm regarding the fragility of cloud security and the sheer scale of data exposure. It fueled widespread discussion about the necessity of robust security audits and compliance in the financial sector.
Political impact
The incident placed immense pressure on major financial institutions to overhaul their cloud security protocols. It led to increased scrutiny from federal regulators regarding the implementation of the Shared Responsibility Model.
13Legal
Paige Thompson was arrested by federal authorities. The incident resulted in internal and external audits for Capital One, leading to significant changes in their cloud security posture.
Prosecutions
- Paige ThompsonArrested and charged
- Charge
- Unauthorized access to computer systems and theft of data
- Jurisdiction
- United States Federal
- Sentence
- Pending court proceedings
Civil lawsuits
- Potential class-action lawsuits from affected consumers
14Aftermath
Policy changes
- Increased industry focus on cloud security best practices and configuration management.
Regulatory changes
- Heightened scrutiny from financial regulators (e.g., OCC, FDIC) regarding cloud security governance.
Security improvements
- Mandatory implementation of network segmentation and least privilege access controls in AWS environments.
- Enhanced internal auditing of firewall rules and security groups.
15Significance and legacy
Significance
This breach is a landmark case study in cloud security, demonstrating that the failure point was not the underlying infrastructure (AWS) but the client's implementation of security controls. It codified the risks associated with misconfigured cloud firewalls, making it a primary reference point for cloud security architecture.
Legacy
The incident permanently elevated the importance of the 'Shared Responsibility Model' in corporate security discourse. It spurred the adoption of automated cloud security posture management (CSPM) tools across the financial and technology sectors.
16Disclosure and media
- Authentication
- Technical analysis of AWS logs and security reports
Media partners
- The New York Times
- Reuters
- TechCrunch
17Field notes
- 01The breach was not due to a zero-day exploit, but rather a simple, yet critical, misconfiguration of a firewall rule.
- 02The incident highlighted the difference between the security *of* the cloud (AWS's job) and the security *in* the cloud (Capital One's job).
18Resolution
Capital One implemented comprehensive security overhauls, including mandatory third-party audits and the adoption of automated security tooling to prevent similar misconfigurations.
19Sources
Official documents
- FBI Press Releases regarding the arrest
References
- [1]The New York Times reporting on the breach
- [2]AWS Security Best Practices Documentation









