Anyone have a copy of the complaint handy? I'd love to read the Government's allegations in more detail. (Edited: complaint, not indictment.)
Capital One Says Breach Hit 100M Individuals in U.S
21–30 of 319 posts
Re: Capital One Says Breach Hit 100M Individuals in U.S
#22If I came across an s3 bucket with my credit application details and I could delete it, I would probably do it and then report to their security team. It’s MY data security they’re being casual with. It occurs to me now that if I did that it would likely be a crime because of the harm to the company. The irony.
Plus what are you going to do with credit card applications anyway? Sell them to a marketing company with some phony story? Or the 'sell them on the darknet to fraudsters in Russia' angle? Unless you're already involved in some dirty business already this isn't very valuable.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#23Earlier quoted context omitted.
DOJ press release: https://www.justice.gov/usao-wdwa/pr/seattle-tech-worker-arr... """ A former Seattle technology company software engineer was arrested today on a criminal complaint charging computer fraud and abuse for an intrusion on the stored data of Capital One Financial Corporation, announced U.S. Attorney Brian T. Moran. PAIGE A. THOMPSON a/k/a erratic, 33, made her initial appearance in U.S. District Court…
intrusion occurred through a misconfigured web application firewall The affidavit states “exfiltrating and stealing information, including credit card applications and other documents”. She used a particular role to exfill from an S3 bucket. Not sure how she got the creds for the role she used to execute List Buckets, etc... Affidavit shows the accused was an employee at the unnamed cloud vendor (clearly AWS at this…
Re: Capital One Says Breach Hit 100M Individuals in U.S
#24Sincerely, another Seattle resident with a mailbox.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#25> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.
If the Seattle "Paige T." is the person with a public Linkedin profile, their recent job history includes "Systems Engineer" at AWS. That could be connected with the breach.
You could be costing some unfortunate woman her job here man. Kind of like when that lady cop broke into that black guy's apartment and blew him away. Then all these people on social media started posting pictures of his coworker on social media and almost cost the woman her position at PwC.
We should try to be a little more responsible than that.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#26I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...
Re: Capital One Says Breach Hit 100M Individuals in U.S
#27Anyone have a copy of the complaint handy? I'd love to read the Government's allegations in more detail. (Edited: complaint, not indictment.)
DOJ press release: https://www.justice.gov/usao-wdwa/pr/seattle-tech-worker-arr... """ A former Seattle technology company software engineer was arrested today on a criminal complaint charging computer fraud and abuse for an intrusion on the stored data of Capital One Financial Corporation, announced U.S. Attorney Brian T. Moran. PAIGE A. THOMPSON a/k/a erratic, 33, made her initial appearance in U.S. District Court…
That seems... unwise. Anyone have a pointer to the github post? Would be interesting to see if it was a "Haha! Look what I did!" kind of thing, or a "Crap, CapOne has an open S3 bucket" kind of post.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#28> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#29Earlier quoted context omitted.
If the Seattle "Paige T." is the person with a public Linkedin profile, their recent job history includes "Systems Engineer" at AWS. That could be connected with the breach.
Woah man. You could be costing some unfortunate woman her job here man. Kind of like when that lady cop broke into that black guy's apartment and blew him away. Then all these people on social media started posting pictures of his coworker on social media and almost cost the woman her position at PwC. We should try to be a little more responsible than that.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#30Anyone have a copy of the complaint handy? I'd love to read the Government's allegations in more detail. (Edited: complaint, not indictment.)
DOJ press release: https://www.justice.gov/usao-wdwa/pr/seattle-tech-worker-arr... """ A former Seattle technology company software engineer was arrested today on a criminal complaint charging computer fraud and abuse for an intrusion on the stored data of Capital One Financial Corporation, announced U.S. Attorney Brian T. Moran. PAIGE A. THOMPSON a/k/a erratic, 33, made her initial appearance in U.S. District Court…
Oh, dear.