More About The Capital One Breach

Capital One Financial is one of the largest US credit card issuers and was recently breached and over 100 million people’s personal data was taken by a hacker. The alleged hacker has now been named as, Paige A. Thompson, who stole a range of data information about people’s bank accounts and personal information from names to birthdates. 
 
Thompson was a systems engineer at Amazon Web Services between 2015 and 2016, about three years before the breach took place. The breach went unnoticed by Amazon and Capital One.
 
Capital One Financial is just the latest business to suffer a data breach. Recently Equifax, the credit reporting company, said it had a $700 million settlement to its 2017 data breach that had affected fifty percent of US people. Other companies that have had breaches include the hotel chain Marriott, retail giants Home Depot and Target.
 
What Happened?
Thompson, 33, who uses the online handle "erratic," allegedly obtained access to Capital One data stored on Amazon's cloud computing platform Amazon Web Services in March. She downloaded the data and stored it on her own servers, according to the complaint. Thompson used the anonymous web browser Tor and a Virtual Private Network in extracting the data, typical methods hackers use to try to mask infiltrations, but she later boasted about the hack on Twitter and a chat group on Slack, posting screenshots as evidence of her exploit.
 
It was only after Thompson began bragging about her feat in a private group chat with other hackers that someone reached out to Capital One to let them know on July 17.
 
Once the informant told Capital One the company closed the vulnerability. The company verified its information had been stolen by July 19 and started tracking Thompson and working with the FBI.  The FBI raided Thompson's residence and seized digital devices. An initial search turned up files that referenced Capital One and "other entities that may have been targets of attempted or actual network intrusions."
 
What Did Thompson Take?
The data breach involves about 100 million people in the US and 6 million in Canada. Capital One said the bulk of the hacked data consisted of information supplied by consumers and small businesses who applied for credit cards between 2005 and early 2019. The hacker also was able to gain some access to fragments of transactional information from dates in 2016, 2017 and 2018.
 
The bank said it believes it is unlikely that the information obtained was used for fraud, but the investigation is ongoing.
Capital One says 140,000 individuals had their Social Security numbers accessed, and another 80,000 had their bank account information accessed.
 
Where there is smoke, there is fire.
  • Organisations such as Italian bank UniCredit and Michigan State University were named in the purported list of files posted by alleged hacker.
  • Michigan State University (MSU) said it was working with the FBI and assessing whether the hacking suspect also got into its systems, though it said it had no knowledge of a breach.
  • Like Capital One, Michigan State is an Amazon Web Services customer. UniCredit, Italy’s largest bank, also said it is investigating the possibility of a breach related to the Capital One incident. 
The issue is simple: Once someone has the keys to the vault, why stop at Capital One?
  • Companies have fervently embraced cloud computing for its speed, ease, cost, and security, giving Amazon and others a large and profitable business.
  • But the widening probe points out a possible weakness: A hacker who figures out a way around the security fence of one cloud customer not only gets to that customer’s data but also has a method that might be usable against others.
  • UniCredit and MSU are mentioned in the postings, as is Ford Motor. A Ford spokeswoman said the company was investigating.
  • The Ohio Department of Transportation, also mentioned, said it, too, was working with the FBI.
And now, the European Central Bank is involved. 
  • UniCredit’s main regulator, the European Central Bank’s supervision arm, said it doesn’t comment on specific banks. The arm looks closely at cybersecurity risks at banks, including through on-site inspections. If UniCredit is involved, expect the General Data Protection Act to kick in. British Airways is contending with a $230 million fine.  Google was charged $75 million and Uber a million. Bring UniCredit, an Italian global bank in 17 countries and $20 billion in revenue, and expect a new wave of industry controls (and fines).
  •  Italian banks have been slow to invest in technology as they have struggled to digest piles of bad loans that accumulated on their balance sheets during the financial and sovereign debt crisis. Only three years ago, 17% of Italian banks loans, whose face value was €360 billion ($401 billion), were sour, according to the Bank of Italy.
If the theory of “once you are in, you are in” holds as the FBI believes, then plenty of financial service companies can be at risk. On the Amazon Web Service website, the Capital One case study mentions many top financial industry users.
 
What to Do
Capital One said it will reach out to those affected using "a variety of channels." Consumers should also obtain copies of their credit reports at AnnualCreditReport.com. By federal law, consumers can receive a free copy of their credit report every 12 months from each of the three big agencies, Equifax, Experian and TransUnion.
 
Look over all of your listed accounts and loans to make sure that all of your personal information is correct and that you authorised the transaction. If you find something suspicious, contact the company that issued the account and the credit-rating agency. 
 
You may also want to consider freezing your credit, which stops thieves from opening new credit cards or loans in your name. This can be done online. Consumers can freeze their credit for free because of a law that President Donald Trump signed last year. Before that, fees were typically $5 to $10 per rating agency.
 
You'll need to remember to temporarily unfreeze your credit if you apply for a new credit card or loan. Also keep in mind that a credit freeze won't protect you from thieves who file a fraudulent tax return in your name or make charges against an existing
account.
 
You should also change your passwords regularly. CreditCards.com industry analyst Ted Rossman recommends using a password aggregator like LastPass that helps create strong, unique passwords for all of your logins.
 
Security Week:             Payments Journal
 
You Might Also Read:
 
Four Questions To Ask After An Attack:
 
Equifax Executives Resign Without Charge:
 
« Surge Of Attacks On Banking & Finance Using N Korean Tools
British Army Reshapes Itself To Fight Cyberwars »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall And Why Does It Matter

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall And Why Does It Matter

See how to use next-generation firewalls (NGFWs) and how they boost your security posture.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

High-Tech Bridge

High-Tech Bridge

High-Tech Bridge SA is a Swiss MSSP provider offering security auditing, source code review and computer forensics.

Beachhead Solutions

Beachhead Solutions

Beachhead's SimplySecure is a configurable, web-based management tool allowing you to remotely secure vulnerable mobile devices in your organization.

Praetorian

Praetorian

Praetorian is an offensive cybersecurity company whose mission is to prevent breaches before they occur.

Swedish Civil Contingencies Agency (MSB)

Swedish Civil Contingencies Agency (MSB)

MSB's Information Assurance Department is responsible for supporting and coordinating work relating to Sweden's national societal information security.

ICTSecurity Portal

ICTSecurity Portal

The ICTSecurity Portal is an interministerial initiative in cooperation with the Austrian economy and acts as a central internet portal for topics related to security in the digital world.

CloudVector

CloudVector

CloudVector's API Detection & Response platform is the only API Threat Protection solution that goes beyond the gateway to provide Shadow API Prevention and Deep API Risk Monitoring and Remediation.

Cynexlink

Cynexlink

Cynexlink offers Managed IT Services with Security, Network, Storage & Cloud solutions for all size of business.

Cryptyk

Cryptyk

CRYPTYK CLOUD is the first complete enterprise-class cloud security solution that includes cloud storage and broad protection against all external and internal threats.

Netenrich

Netenrich

The Netenrich operations intelligence platform is built from the ground up to help enterprises resolve everyday and futuristic problems for stable, secure environments and infrastructures.

Bloc Ventures

Bloc Ventures

Bloc Ventures is an investment company providing long-term, ‘patient’ equity capital to early stage unquoted deep technology companies.

CyberNet Albania

CyberNet Albania

Cybernet Albania has been providing IT support and services to small businesses since 2016. We strive to eliminate your IT issues before they cause downtime and impact your operations.

Across Verticals

Across Verticals

Across Verticals is a boutique cyber security consulting firm that specializes in holistic, deeply technical and end to end cyber security advisory services based on industry best practices.

tru.ID

tru.ID

We’re tru.ID, and we're reimagining mobile authentication, one API at a time.

SoftwareONE

SoftwareONE

SoftwareONE is a leading global provider of end-to-end software and cloud technology solutions.

Quantum Security Services

Quantum Security Services

Quantum Security Services is a specialist information security firm providing a range of risk, compliance and technical security services.

Miggo Security

Miggo Security

Miggo is the first Application Detection and Response (ADR) platform on a mission to stop application breaches.