Capital One Reveals Massive Data Breach Affecting 106 Million People
Capital One announces a major data security incident that exposes the personal information of approximately 106 million credit card applicants and customers. The FBI arrests the suspected perpetrator, and the bank confirms that no credit card account numbers or login credentials are compromised.
Capital One announces a massive data security incident that exposes the personal information of approximately 106 million individuals in the United States and Canada. The bank discovers on July 19 that an outside individual exploits a configuration vulnerability to access data related to credit card applicants and customers. Capital One immediately fixes the vulnerability and alerts federal law enforcement.
The FBI arrests the person responsible for the breach, and the suspect remains in custody. Capital One states that it is unlikely the accessed information is used for fraud or shared by the attacker. The largest category of compromised data includes credit card applications submitted between 2005 and early 2019, which contain names, addresses, dates of birth, and self-reported income.
While the hacker obtains portions of existing customer data such as credit scores, balances, and payment history, Capital One confirms that no credit card account numbers or login credentials are compromised. Additionally, over 99 percent of Social Security numbers remain secure during the event. Chairman and CEO Richard D. Fairbank issues a public apology, expressing deep regret and a commitment to making things right for those affected.