Former AWS Engineer Charged in Massive Capital One Data Breach
A former Amazon Web Services software engineer faces federal charges after allegedly exploiting a firewall misconfiguration to steal data from over 100 million Capital One customers. Authorities track down the suspect through social media posts and an anonymous tip sent directly to the bank.
The FBI arrests 33-year-old software engineer Paige Thompson for allegedly hacking into Capital One and stealing the personal data of over 100 million people. Authorities track down the Seattle resident after she discusses the breach online using the alias "erratic" and an anonymous tipster notifies the bank about leaked data on GitHub. Investigators believe Thompson acts alone in this massive digital break-in.
The breach stems from a misconfigured firewall on a Capital One server hosted by a cloud computing provider. This specific vulnerability allows the hacker to execute commands that access the bank's cloud storage buckets, exposing sensitive information tied primarily to credit card applications. Amazon Web Services confirms Thompson previously worked for them but stresses that the underlying cloud infrastructure remains uncompromised and functions exactly as designed.
Thompson now faces federal charges of computer fraud and abuse for the unauthorized intrusion into stored data. The incident highlights the critical importance of web application configuration rather than flaws in cloud infrastructure, as Capital One estimates the breach costs up to $150 million. The stolen data includes approximately 120,000 Social Security numbers alongside other personal applicant details.