Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

31–40 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#31

I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...

Good lord.

-Paige left code used in the "attack" on her GitHub.

-Paige left text files with unencrypted data there, too.

-Paige openly posted about it in an open (!!!) Slack channel and publicly named her VPN service of choice, which of course, matched access logs AND GitHub server logs. (Also tor, which the FBI agent was able to confirm and add yet another data point)

-Paige said "I have a leak proof IPredator router setup." nice.

Nice opsec there. Sheesh.

EDIT: Thanks for the PACER share, by the way.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#32

Earlier quoted context omitted.

DOJ press release: https://www.justice.gov/usao-wdwa/pr/seattle-tech-worker-arr... """ A former Seattle technology company software engineer was arrested today on a criminal complaint charging computer fraud and abuse for an intrusion on the stored data of Capital One Financial Corporation, announced U.S. Attorney Brian T. Moran. PAIGE A. THOMPSON a/k/a erratic, 33, made her initial appearance in U.S. District Court…

Sounds less like intrusion and more like accidental exposure by Capital One.

[deleted]

Re: Capital One Says Breach Hit 100M Individuals in U.S

#33
post #24

Dear "Seattle Woman": while you're in there, please dump Capital One's junk mail database, and set their address label printer on fire. Sincerely, another Seattle resident with a mailbox.

They really do send out a whole lotta junk mail, even here in Canada. I don't see other banks doing that.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#34
post #28

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

The court filing directly says "s3", so yeah, it's Amazon.

[deleted]

Re: Capital One Says Breach Hit 100M Individuals in U.S

#36

I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...

Sorry to be pedantic, but this is merely a complaint. This is the initial document used to get an arrest warrant. An indictment is returned by a grand jury.

http://www.mololamken.com/news-knowledge-29.html

Re: Capital One Says Breach Hit 100M Individuals in U.S

#37

A Linkedin profile that is now disabled _used_ to exist for a Paige Thompson in Seattle that worked at Amazon Web Services (AWS). It's the first result on Google: https://www.google.com/search?q="paige+thompson"+Amazon+Web+...

Delete that (or edit to to be blank if you can't). That's a common name, you have no idea if it's the same person.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#38
post #16
post #4

> Capital One Financial Corp. lost data from as many as tens of millions of credit card applications after a Seattle woman hacked into a cloud-computing company server > The cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers I can’t tell whether the company virtual server got hacked or whether the cloud provider was who got breached. Hopefully just the vm

Well, the main cloud Capital One uses is Amazon as far as I know. If you think about the attack vectors here, it was most definitely the virtual server that got attacked. If it was the cloud provider (Amazon), there are a lot of safeguards that these banks use to make sure that any data that touches the shared server persistent storage is encrypted. And when I say safeguards, I mean automation to make sure that this…

"there are a lot of safeguards that these banks use to make sure that any data that touches the shared server persistent storage is encrypted. And when I say safeguards, I mean automation to make sure that this sort of scenario shouldn't ever happen." ROTFLMAO....you have clearly never worked for a bank, no offense mate. Capital left this shit in plain text on an S3 bucket, I guarantee you

Re: Capital One Says Breach Hit 100M Individuals in U.S

#39

I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...

Good lord. -Paige left code used in the "attack" on her GitHub. -Paige left text files with unencrypted data there, too. -Paige openly posted about it in an open (!!!) Slack channel and publicly named her VPN service of choice, which of course, matched access logs AND GitHub server logs. (Also tor, which the FBI agent was able to confirm and add yet another data point) -Paige said "I have a leak proof IPredator route…

It says she posted on "social media" (Twitter) about it, claiming to have Capital One information, "and that she recognizes that she acted illegally".

Nothing about Opsec here. She basically asked them to arrest her. Probably had some of the usual motivations: "look at me I'm clever", "look at this stupid big company with bad security", or maybe used the opportunity for some political thing with banks. Not the sophisticated hacker type. But who knows.

Edit: originally I asked about her Github profile listed in the complaint as paigea(5x * characters)thompson but was iffy on whether that was okay on HN.

Post reply on HN