This Monday, July 22, 2019, photo shows Capital One mailing in North Andover, Mass. Capital One says a hacker got access to the personal information of over 100 million individuals applying for credit. The McLean, Virginia-based bank said Monday, July 29, 2019, it found out about the vulnerability in its system July 19 and immediately sought help from law enforcement to catch the perpetrator. (AP Photo/Elise Amendola)

This Monday, July 22, 2019, photo shows Capital One mailing in North Andover, Mass. Capital One says a hacker got access to the personal information of over 100 million individuals applying for credit. The McLean, Virginia-based bank said Monday, July 29, 2019, it found out about the vulnerability in its system July 19 and immediately sought help from law enforcement to catch the perpetrator. (AP Photo/Elise Amendola)

Capital One target of massive data breach

Paige A. Thompson was charged with a single count of computer fraud and abuse

A security breach at Capital One Financial, one of the nation’s largest issuers of credit cards, compromised the personal information of about 106 million people, and in some cases the hacker obtained Social Security and bank account numbers.

It is among the largest security breaches of a major U.S. financial institution on record. The bank’s stock dipped 6% at the opening of trading Tuesday.

Paige A. Thompson, who uses the online handle “erratic” — was charged with a single count of computer fraud and abuse in U.S. District Court in Seattle. Thompson made an initial appearance in court and was ordered to remain in custody pending a detention hearing Thursday.

Federal agents began tracking Thompson online after being notified by Capital One of a possible breach in July.

On June 18, Thompson sent a message on Twitter to another user saying, “Ive basically strapped myself with a bomb vest, (expletive) dropping capitol ones dox and admitting it.”

The FBI raided Thompson’s residence Monday and seized digital devices. An initial search turned up files that referenced Capital One and “other entities that may have been targets of attempted or actual network intrusions.”

Thompson was a systems engineer at Amazon Web Services between 2015 and 2016, about three years before the breach took place.

While that service is used by Capital One, there is no evidence that Amazon’s cloud system was involved in the breach.

“AWS was not compromised in any way and functioned as designed,” a company spokesperson said Tuesday. “The perpetrator gained access through a misconfiguration of the web application and not the underlying cloud-based infrastructure. As Capital One explained clearly in its disclosure, this type of vulnerability is not specific to the cloud.”

Capital One Financial Corp. was notified by a third party on July 19 that their data had appeared on the code-hosting site GitHub, which is owned by Microsoft. The McLean, Virginia, company says it immediately notified the FBI.

The FBI said a Twitter user who went by “erratic” sent a user direct messages warning about distributing the bank’s data, including names, birthdates and Social Security numbers. That user reported the message to Capital One.

ALSO READ: FTC fines Facebook $5B, adds limited oversight on privacy

Capital One said it believes it is unlikely that the information was used for fraud, but the investigation is ongoing.

The data breach involves about 100 million people in the U.S. and 6 million in Canada.

The bank said the bulk of the hacked data consisted of information supplied by consumers and small businesses who applied for credit cards between 2005 and early 2019. In addition to data such as phone numbers, email addresses, dates of birth and self-reported income, the hacker was also able to access credit scores, credit limits and balances, as well as fragments of transaction information from a total of 23 days in 2016, 2017 and 2018.

“While I am grateful that the perpetrator has been caught, I am deeply sorry for what has happened,” said Capital One CEO Richard Fairbank. “I sincerely apologize for the understandable worry this incident must be causing those affected and I am committed to making it right.”

Capital One Financial Corp., the nation’s seventh-largest commercial bank with $373.6 billion in assets as of June 30, is the latest U.S. company to suffer a major data breach in recent years.

In 2017, a data breach at Equifax, one of the major credit reporting companies, exposed the Social Security numbers and other sensitive information of roughly half of the U.S. population.

Last week, Equifax agreed to pay at least $700 million to settle lawsuits over the breach in a settlement with federal authorities and states. The agreement includes up to $425 million in monetary relief to consumers.

READ MORE: Equifax hack compromised 100,000 Canadians’ personal data

Many major banks have sought to stem the risk of data breaches in recent years. JPMorgan Chase, Bank of America and Citibank began replacing customers’ debit cards several years ago with more secure chip-based cards. While the cards with chips are common these days, many merchants still rely on the older, less secure card-swiping equipment. Credit card companies have also beefed up fraud monitoring in the wake of high-profile data breaches that hit retailers such as Target and Home Depot.

The average cost of a data breach in the U.S. last year was just under $8 million, according to a study by IBM Security and Ponemon Institute.

A public defender appointed to represent Thompson did not immediately return an email seeking comment.

___

Associated Press reporter Alex Veiga in Los Angeles contributed to this article.

Gene Johnson, The Associated Press


Like us on Facebook and follow us on Twitter.

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Dr. Bonnie Henry, provincial health officer, updates British Columbians about COVID-19 at a press conference earlier this week. (B.C. Government image)
B.C.’s 1st case of COVID-19 confirmed a year ago today

Here’s a look at some of the key dates in the province’s fight against the novel coronavirus

Toronto’s Mass Vaccination Clinic is shown on Sunday January 17, 2021. THE CANADIAN PRESS/Frank Gunn
Interior Health reports 2 more deaths, 83 new COVID-19 cases

Health authority also identifies new virus cluster in Fernie

Hotel Kimberley owner Anthony Edwards met with representatives of Mainroad and the City of Kimberley to discuss potential solutions for the amount of ice and road debris that gets plowed onto his sidewalk for him to have to shovel. The next day, he was met with the same problem. Photo submitted.
Hotel Kimberley owner seeks solution to ice, debris plowed onto sidewalk

Hotel Kimberley owner Anthony Edwards wants a solution after years of complaining… Continue reading

The Cranbrook Climate Hub will be hosting a webinar this coming Friday (January 29) that focuses on sustainable jobs. (Image by StartupStockPhotos from Pixabay)
Cranbrook Climate Hub to host webinar on sustainable jobs

Bruce Wilson, former General Manager for Shell, will speak on ‘looking beyond Keystone XL’

Rob Davidson, manager at Buckhorn and Main, created a Facebook group which has connected people and given them a positive distraction throughout the lockdown. Paul Rodgers photo.
Rob Davidson’s Facebook food group a positive, connecting presence throughout pandemic

Since the pandemic hit and lockdown began, people have been in need… Continue reading

Crews with Discovery Channel film as an Aggressive Towing driver moves a Grumman S2F Tracker aircraft around a 90-degree turn from its compound and onto the road on Saturday, Jan. 23, 2021. It was the “most difficult” part of the move for the airplane, one organizer said. (Jenna Hauck/ Chilliwack Progress)
VIDEO: Vintage military plane gets towed from Chilliwack to Greater Victoria

Grumman CP-121 Tracker’s eventual home the British Columbia Aviation Museum on Vancouver Island

A lone passenger stands outside the International Arrivals area at Pearson Airport in Toronto on Tuesday, Jan. 26, 2021. As the federal government prepares to slap new restrictions on foreign arrivals, Health Canada data suggest a growing number of infections directly connected to international travel. THE CANADIAN PRESS/Frank Gunn
Holiday season vacations coincide with rise in COVID-19 travel-related cases

Between Nov. 30 and Dec. 27, 86,953 people flew into Canada from the United States

Gov.Gen Julie Payette walks in the chamber after greeting Senators before delivering the Speech from the Throne, at the Senate of Canada Building in Ottawa, on Wednesday, Sept. 23, 2020. THE CANADIAN PRESS/Justin Tang
Report details yelling, screaming and aggressive conduct at Rideau Hall under Payette

Report says employees did not feel they had a place to go with their complaints

Rodney and Ekaterina Baker have been ticketed and charged under the Yukon’s Civil Emergency Measures Act for breaking isolation requirements in order to sneak into a vaccine clinic and receive Moderna vaccine doses in Beaver Creek. (Facebook/Submitted)
B.C. couple accused of flying to Yukon to get COVID-19 vaccine to appear in court

If convicted, the pair could serve up to six months in jail

Grad student Marisa Harrington and her supervisor Lynneth Stuart-Hill say preliminary results from a study into the affects of stress on hospital nurses show an impact on sleep and heart variability. (Courtesy of Marisa Harrington)
University of Victoria study shows stress impact on B.C. nurses

Stress may be impacting sleep, heart health of hospital nurses in Victoria region

Join Black Press Media and Do Some Good
Join Black Press Media and Do Some Good

Pay it Forward program supports local businesses in their community giving

Sooke’s Amy McLaughlin holds Theodore, a bunny who will be going to a new owner in Nanaimo within the coming days if all goes will at an upcoming bunny play-date. (Aaron Guillen/News Staff)
Vancouver Island woman looking to hop into bigger space for bunny rescue operation

Amy McLaughlin has rescued more than 400 bunnies, pushing for the capacity to help more

Keith Thorpe/Peninsula Daily News
Search called off for small plane that went down in rough water south of Victoria

Plane bound for Port Angeles from Alaska believed to have one occupant, an Alaskan pilot

Royal B.C. Museum conservator Megan Doxsey-Whitfield kneels next to a carved stone pillar believed to have significance as a First Nations cultural marker by local Indigenous people. The pillar was discovered on the beach at Dallas Road last summer. Museum curatorial staff have been working with Songhees and Esquimalt Nation representatives to gain a clearer picture of its use. (Photo courtesy Royal BC Museum)
Stone carving found on Victoria beach confirmed Indigenous ritual pillar

Discussion underway with the Esquimalt and Songhees about suitable final home for the artifact

Most Read