In July 2019 former Amazon Web Services engineer Paige Thompson exploited a server-side request forgery flaw in a misconfigured web application firewall to download data on more than 100 million Capital One customers and credit-card applicants across the U.S. and Canada, in one of the largest financial-data breaches on record. Prosecutors said Thompson, operating under the alias "erratic," had built a scanning tool while at Amazon that swept AWS for misconfigured accounts and used it to hack more than 30 entities including Capital One, exfiltrating payment history, contact information, credit scores, roughly 120,000 Social Security numbers and about 77,000 linked bank-account numbers, and planting cryptocurrency-mining software on victim servers. The intrusion was uncovered after an anonymous tip pointed the FBI to her GitHub post containing the stolen files, leading to her arrest later that month. Capital One agreed in 2020 to pay an $80 million OCC civil penalty for inadequate cloud-security controls and in December 2021 settled customer class-action litigation for $190 million; U.S. Attorney Nick Brown told the court her conduct caused more than $250 million in damages. A Seattle federal jury convicted Thompson in June 2022 on wire fraud and five Computer Fraud and Abuse Act counts, and in October 2022 Judge Robert Lasnik sentenced her to time served plus five years of probation. The case became the canonical example of the cloud shared-responsibility model and a turning point for cloud-misconfiguration scrutiny across the financial sector.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

