Paige Thompson, a former Amazon Web Services engineer in Seattle, exploited a misconfigured web application firewall in 2019 to exfiltrate data on more than 100 million Capital One customers, including approximately 120,000 Social Security numbers and 77,000 bank account numbers, in one of the largest U.S. financial-data breaches on record. Prosecutors showed that Thompson built a scanning tool on AWS to hunt for misconfigured accounts, then used the access to download data from more than 30 entities besides Capital One, whose internal system treated her queries as coming from a "friendly" computer and served the data. Arrested in July 2019, she was held until November 2019, then released on pretrial supervision for more than three years. A Seattle federal jury convicted her in June 2022 on seven counts including wire fraud, unauthorized access to a protected computer, and damaging a protected computer under the Computer Fraud and Abuse Act, while acquitting her of intent to commit fraud with the personal data. On October 4, 2022, U.S. District Judge Robert Lasnik sentenced her to time served plus five years of probation, citing her mental-health history; U.S. Attorney Nick Brown said she had caused more than $250 million in damages. Capital One had separately agreed to an $80 million OCC penalty in 2020 and a $190 million class-action settlement in December 2021.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.


