In July 2019, Capital One reported one of the largest financial sector data breaches in U.S. history. Over 100 million people in the United States and Canada had their credit card application data, customer status records, and in some cases Social Security numbers and bank account numbers stolen.
About Capital One
Capital One is one of the largest banks in the United States, ranking among the top ten by assets and serving over 100 million customers. The company employs around 50,000 people and reported revenues of approximately $28 billion in 2018, the year before the breach.
Credit cards are the heart of the business, and Capital One is the third largest credit card issuer in the country, with its very recognizable ad slogan, “What’s in your wallet?” The company holds a large amount of sensitive consumer financial data, including application records, credit histories, transaction data, and identity information going back years, which made it a high-value target.

What led to a vulnerable state?
Starting in 2015, Capital One began migrating their IT operations from on-premises to the cloud. Specifically, they chose to migrate to Amazon Web Services (AWS). During this process, two vulnerabilities were introduced: a misconfiguration in their web application firewall (WAF), and an AWS IAM role that was given too much access to data.
The WAF misconfiguration allowed any attacker to reach the AWS Instance Metadata Service on hosts behind the WAF. This metadata service ran alongside each AWS EC2 instance1 and provided a lot of information, including IAM credentials.
The IAM role that these credentials provided access to, had access to over 700 S3 buckets2, which contained information related to all Capital One customers.
The Attack
The attacker first ran a vulnerability scan against Capital One’s network on March 4th, 2019. Initial access was achieved eight days later on March 12th, via the WAF misconfiguration previously mentioned. The attacker discovered the overpermissioned IAM role and the data it granted access to. Most of the data was stolen ten days later, between March 22nd and 23rd. The entire attack comprised less than a month.
A month later, on the 21st of April, the attacker publicly posted exploit instructions3 using their GitHub account, which also hosted their resume. Three months later, on July 17th, a security researcher discovered the attacker’s exploit instructions and reported the incident to Capital One via their vulnerability disclosure program (VDP). How the researcher came to discover the attacker’s post is unclear. The resume and clear identity on the Github account attached to the exploit details, made an arrest straightforward for law enforcement.
Capital One notified the public of the breach on July 29, 2019. The same day, the FBI arrested the attacker and seized their electronics, on which a copy of the stolen data was found.
About the Attacker
Paige Thompson was a former software engineer at Amazon Web Services, working there until 2016. Her prior experience at AWS provided direct familiarity with AWS environments and common misconfigurations. By the time she was arrested, prosecutors alleged she had breached more than 30 organizations using similar methods, including Vodafone, Ford Motor Company, UniCredit, Michigan State University, and the Ohio Department of Transportation.
Her motivations are hard to pinpoint. As far as we know, she never attempted to sell the data she stole. In addition to stealing data, she installed cryptocurrency mining software on the cloud resources she had compromised, using victims’ compute capacity for her own profit. She was also vocal about what she was doing, eventually posting details of the Capital One exploit to a public post and boasting about stolen files in a Slack group open to the public.
Impact
Capital One’s total losses from the breach ran well into the hundreds of millions of dollars. Between the $72 million in direct breach expenses reported in its SEC 10-K filing, the $80 million OCC fine for failing to establish effective risk assessment processes before migrating to the cloud, and the $190 million class action settlement fund, the direct, measurable losses alone exceeded $300 million. This sum does not account for $34 million recovered through insurance, legal expenses, or breach remediation expenses.
Roughly 100 million people in the United States and 6 million in Canada had their data accessed. The exposed information came from credit card applications submitted between 2005 and early 2019, including names, addresses, zip codes, phone numbers, email addresses, dates of birth, and self-reported income.
Beyond application data, the attacker also obtained customer data such as credit scores, credit limits, balances, payment history, and contact information. Approximately 140,000 Social Security numbers belonging to U.S. customers were compromised, along with roughly 80,000 bank account numbers.
For Canadian customers, ~1 million Social Insurance Numbers were exposed.
No credit card account numbers or login credentials were compromised in the incident. Capital One had applied tokenization to Social Security numbers and bank account numbers in some places, but inconsistent implementation across its systems meant those fields were still accessible in others.
Legacy & Takeaways
Thompson was arrested the same day Capital One went public about the breach. She was convicted of seven federal crimes in June 2022 and sentenced that October. Her sentence was time served, 5 years of probation with 3 years of home confinement, 250 hours of community service, and $40.7 million in restitution. She was not sentenced to any additional time in prison.
Prosecutors appealed the ruling as too lenient, and in March 2025, the Ninth Circuit vacated the original sentence and remanded for resentencing. In November of 2025, the court reimposed the original sentence, stating that imprisonment would be “greater-than-necessary punishment”.
The OCC’s enforcement action outlined many issues with Capital One’s cloud migration. It had not implemented appropriate network security controls, data loss prevention controls, or effective alert handling for the new environment. The breach went undetected for months because the monitoring that should have flagged an unusual volume of S3 data being synced outbound was not in place or not acting on what it saw.
This incident became a case study for proper cloud security hygiene and applying the principle of least privilege to IAM roles. It continues to provide a useful case study for students and experienced practitioners alike.
Appendix A: Control Failures
The control failures below are drawn from the NIST CSF 1.1 analysis conducted by Novaes, Madnick, et al. in their MIT Sloan case study of the Capital One breach. Each failure maps to one or more attack steps identified in the FBI indictment and technical analysis.
ATT&CK Navigator Summary: Primary Tactics Leveraged
Initial Access ⇒ Credential Access ⇒ Execution ⇒ Discovery ⇒ Exfiltration
The attack is notable for the insufficient IAM controls that allowed credential theft (CF-4) and the absence of outbound traffic monitoring that allowed exfiltration to go undetected for months (CF-6). Critically, Capital One possessed the CloudTrail logs capturing every attacker action in real time but had no active alerting configured to act on them. The attack required no novel techniques. Every step was enabled by failures that existing compliance frameworks already had controls for.
MITRE D3FENSE
Appendix B: References
Breach Info
https://cams.mit.edu/wp-content/uploads/capitalonedatapaper.pdf
https://www.huntress.com/threat-library/data-breach/capital-one-data-breach
Government Sources
https://www.wyden.senate.gov/imo/media/doc/081319 Amazon Letter to Sen Wyden RE Consumer Data.pdf
https://www.federalreserve.gov/newsevents/pressreleases/files/enf20200806a1.pdf
https://www.occ.treas.gov/news-issuances/news-releases/2020/nr-occ-2020-101.html
https://www.occ.gov/static/enforcement-actions/ea2020-036.pdf
https://www.occ.gov/static/enforcement-actions/ea2020-037.pdf
https://www.occ.gov/static/enforcement-actions/ea2022-037.pdf
Court Case
https://www.justice.gov/usao-wdwa/united-states-v-paige-thompson
https://www.justice.gov/usao-wdwa/page/file/1194001/dl?inline
https://www.justice.gov/usao-wdwa/page/file/1405446/dl?inline
https://law.justia.com/cases/federal/appellate-courts/ca9/22-30179/22-30179-2025-03-17.html
Class Action Info
Attacker Info
https://cyberscoop.com/capital-one-hacker-not-guilty-paige-thompson/
https://www.bankingdive.com/news/ex-amazon-employee-convicted-over-2019-capital-one-breach/625734/
https://cyberscoop.com/court-reimposes-original-sentence-for-capital-one-hacker/
Appendix C: Full Timeline
March 4, 2019 - Capital One subsequently determined that the attacker first ran a vulnerability scan on their network this day.
March 12, 2019 - The attacker first accessed Capital One’s network.
March 22-23, 2019 - External party leveraged misconfiguration to access credit card application data, exfiltrating data on hundreds of millions of users.
April 2, 2019 - Capital One believes the attacker accessed the environment again this day
April 19, 2019 - Capital One believes the attacker accessed the environment again this day
April 21, 2019 - The attacker accessed the environment once again and posted instructions on Github detailing how to execute the exploit to access Capital One data, under the username netcrave. The attacker’s page also linked to their GitLab, which contained their resume, full name, and address
June 27, 2019 - The attacker publicly posted on a Slack group (using the username Erratic), claiming to have files from the breach
July 17, 2019 - A researcher looking through GitHub was able to find the post and reported it via CapitalOne’s responsible disclosure contact, some sources claim that researcher Kat Valentine was privately messaged on Twitter by Thompson, who then reported it.
July 19, 2019 - Capital One discovered the security incident
July 29, 2019 - Publicly announced by Capital One. Paige Thompson is arrested by the FBI, and her electronics were seized. A copy of the data was found among the storage devices.’
August 6, 2019 - Senator Elizabeth Warren sent a letter to Capital One requesting information on the breach and accountability for security failures,
August 15, 2019 - Thompson’s initial hearing was scheduled.
August 28, 2019 - Thompson was indicted by a federal grand jury on charges related to her unauthorized intrusion into stored data of Capital One and more than 30 other entities, including a state agency, a telecommunications conglomerate, and a public research university.
August 6, 2020 - The OCC (independent bureau of the Treasury, in charge of all national and international banks in the country) fines Capital One $80 million for “the bank’s failure to establish effective risk assessment processes prior to migrating significant information technology operations to the public cloud environment and the bank’s failure to correct the deficiencies in a timely manner.”
August 4, 2020 - The Federal Reserve Board of Governors issued a Cease and Desist Order against Capital One Financial Corporation, requiring the company to strengthen its risk management program and internal controls.
January 27, 2021 - Capital One discovered approximately 4,700 additional U.S. credit card customers or applicants whose Social Security Numbers were among the data accessed but not previously known.
February 7, 2022 - A U.S. federal court approves a class action settlement relating to the cyber incident.
March 14, 2022 - Thompson’s trial begins in the U.S. District Court in Seattle
June 17, 2022 - Thompson is found guilty of seven federal crimes. Jury drops 2 charges.
September 15, 2022 - Thompson is scheduled for sentencing
October 4, 2022 - Sentenced to 5 years probation plus time already served, allowing Thompson to avoid prison.
March 19, 2025 - Appealed by prosecutors, arguing that, with a maximum sentence of 210 months, this was too lenient.
November 3, 2025 - The court reimposes the original sentence, stating that imprisonment would be “greater-than-necessary punishment”
EC2 is effectively virtual machines in AWS cloud - you run and manage the whole OS yourself, in AWS’s cloud
S3 buckets are the equivalent of file shares or Google Drive, but in the cloud - they store unstructured data, files, whatever you want to store. There have been many data leaks over the years due to misconfigured S3 buckets.
In a GitHub Gist. Gists are basically very simple, standalone text files.







