Seattle Woman Charged in Massive 106 Million Person Capital One Breach

Federal prosecutors charge a former Amazon systems engineer with stealing personal data from 106 million Capital One credit card applicants. The breach exposes sensitive information but spares the vast majority of Social Security numbers and all credit card account numbers.

Federal prosecutors charge Seattle resident Paige Thompson with stealing personal data from approximately 106 million Capital One credit card applicants. The hacker downloads nearly 30 gigabytes of sensitive information from a rented cloud server, affecting 100 million people in the United States and six million in Canada. The compromised data includes names, addresses, dates of birth, and roughly 140,000 Social Security numbers.

Capital One states that no credit card account numbers or login credentials suffer compromise in the incident, and over 99 percent of Social Security numbers remain safe. The stolen information primarily consists of application details collected between 2005 and early 2019 from consumers and small businesses. The financial institution learns about the theft through an anonymous email tip on July 17.

The tipster alerts Capital One that its leaked data sits openly on the software development platform Github under an account linked to Thompson. Investigators discover that the accused previously works as a systems engineer at the cloud hosting provider involved in the breach. Furthermore, Thompson openly discusses the hack on social media using the nickname "erratic" in the months leading up to the arrest.

Read More at the original source →