Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

41–50 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#41
post #39

Earlier quoted context omitted.

Good lord. -Paige left code used in the "attack" on her GitHub. -Paige left text files with unencrypted data there, too. -Paige openly posted about it in an open (!!!) Slack channel and publicly named her VPN service of choice, which of course, matched access logs AND GitHub server logs. (Also tor, which the FBI agent was able to confirm and add yet another data point) -Paige said "I have a leak proof IPredator route…

It says she posted on "social media" (Twitter) about it, claiming to have Capital One information, "and that she recognizes that she acted illegally". Nothing about Opsec here. She basically asked them to arrest her. Probably had some of the usual motivations: "look at me I'm clever", "look at this stupid big company with bad security", or maybe used the opportunity for some political thing with banks. Not the sophis…

Almost certainly deactivated/seized and part of evidence. With some googling you can find her Keybase and other pages aplenty if you like. Almost all her content is scrubbed from the Internet, however.

(this person's original comment was asking for her github profile)

Re: Capital One Says Breach Hit 100M Individuals in U.S

#42
post #3

Anyone have a copy of the complaint handy? I'd love to read the Government's allegations in more detail. (Edited: complaint, not indictment.)

DOJ press release: https://www.justice.gov/usao-wdwa/pr/seattle-tech-worker-arr... """ A former Seattle technology company software engineer was arrested today on a criminal complaint charging computer fraud and abuse for an intrusion on the stored data of Capital One Financial Corporation, announced U.S. Attorney Brian T. Moran. PAIGE A. THOMPSON a/k/a erratic, 33, made her initial appearance in U.S. District Court…

>the information sharing site GitHub

I mean if that's what some legal news site calls it… :P

Re: Capital One Says Breach Hit 100M Individuals in U.S

#44
post #25
post #18

Earlier quoted context omitted.

If the Seattle "Paige T." is the person with a public Linkedin profile, their recent job history includes "Systems Engineer" at AWS. That could be connected with the breach.

Woah man. You could be costing some unfortunate woman her job here man. Kind of like when that lady cop broke into that black guy's apartment and blew him away. Then all these people on social media started posting pictures of his coworker on social media and almost cost the woman her position at PwC. We should try to be a little more responsible than that.

I think you're overreacting. Their name is public, and I didn't link to the public profile, nor did I say the public profile was the person in question. Only that if it is them, then having a work history of AWS adds an interesting dimension.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#45
post #36

I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...

Sorry to be pedantic, but this is merely a complaint. This is the initial document used to get an arrest warrant. An indictment is returned by a grand jury. http://www.mololamken.com/news-knowledge-29.html

Edited, thanks.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#46

Earlier quoted context omitted.

DOJ press release: https://www.justice.gov/usao-wdwa/pr/seattle-tech-worker-arr... """ A former Seattle technology company software engineer was arrested today on a criminal complaint charging computer fraud and abuse for an intrusion on the stored data of Capital One Financial Corporation, announced U.S. Attorney Brian T. Moran. PAIGE A. THOMPSON a/k/a erratic, 33, made her initial appearance in U.S. District Court…

intrusion occurred through a misconfigured web application firewall The affidavit states “exfiltrating and stealing information, including credit card applications and other documents”. She used a particular role to exfill from an S3 bucket. Not sure how she got the creds for the role she used to execute List Buckets, etc... Affidavit shows the accused was an employee at the unnamed cloud vendor (clearly AWS at this…

[deleted]

Re: Capital One Says Breach Hit 100M Individuals in U.S

#48

I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...

Good lord. -Paige left code used in the "attack" on her GitHub. -Paige left text files with unencrypted data there, too. -Paige openly posted about it in an open (!!!) Slack channel and publicly named her VPN service of choice, which of course, matched access logs AND GitHub server logs. (Also tor, which the FBI agent was able to confirm and add yet another data point) -Paige said "I have a leak proof IPredator route…

Generally having a screenshot of someone telling you "don't go to jail plz" in a criminal complaint against you is not ideal.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#49
post #25
post #18

Earlier quoted context omitted.

If the Seattle "Paige T." is the person with a public Linkedin profile, their recent job history includes "Systems Engineer" at AWS. That could be connected with the breach.

Woah man. You could be costing some unfortunate woman her job here man. Kind of like when that lady cop broke into that black guy's apartment and blew him away. Then all these people on social media started posting pictures of his coworker on social media and almost cost the woman her position at PwC. We should try to be a little more responsible than that.

According to the publicly released report, the woman that was arrested used to work for the "cloud computing company" that was involved.

https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...

Re: Capital One Says Breach Hit 100M Individuals in U.S

#50

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

Per the complaint, it doesn't sound like the bucket was exposed to the world. Rather, security credentials were "obtained":

> Capital One determined that the first command, when executed, obtained security credentials for an account named XXXX-WAF-Role, that in turn, enabled access to certain of Capital One's folders at the Cloud Computing Company.

Unsure how one would obtain credentials for an IAM Role, but the above verbatim from the complaint.

* edited to reflect this is lifted from the complaint, not indictment.

Post reply on HN