Capital One Says Breach Hit 100M Individuals in U.S
211–220 of 319 posts
Re: Capital One Says Breach Hit 100M Individuals in U.S
#212Anyone have a copy of the complaint handy? I'd love to read the Government's allegations in more detail. (Edited: complaint, not indictment.)
Re: Capital One Says Breach Hit 100M Individuals in U.S
#213> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.
The court filing directly says "s3", so yeah, it's Amazon.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#214What was Slack's role in all of this? They appear to have turned over historical images and chat logs, not just for the person indicted, but even others in the same channel. Did the FBI ask nicely or was there actually some formal process?
The entire server chat log is a few Google searches away.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#215Earlier quoted context omitted.
I would imagine complete credit card applications contain the type of information identity thieves would be willing to pay good money for.
I think the point is: unless the hacker is already aware of how to sell PII of this nature and how to move "good money" then a hack like this is for naught. Reading the mistakes made in the hack itself makes me wonder if black markets and money laundering are a skill they posses.
If you were lazy you could just hit up an existing vendor and ask them to sell your data in batches.
I’m not saying this would be a good idea, but it certainly wouldn’t be very difficult.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#216Earlier quoted context omitted.
Miss the LevelMoney folks... Yeah AWS can’t protect you against a misconfigured environment
Are there AWS experts who can do some sort of quick audit or "sanity check" of an environment's configurations? AWS almost makes it too easy for someone who only sort of knows what they're doing (like me) to get things up and running.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#217Earlier quoted context omitted.
Actually looks like she worked for Amazon on S3. So there might have been some insider knowledge. From the complaint below, and googling her name you can find her resume I won't link it here, but here's a screenshot of a snippet: https://i.imgur.com/NezWVKw.png
Unlikely. S3 was publicly rebuilt in the wake of the 2017 S3pocalypse.
Re: Capital One Says Breach Hit 100M Individuals in U.S
#218Re: Capital One Says Breach Hit 100M Individuals in U.S
#219Re: Capital One Says Breach Hit 100M Individuals in U.S
#220If I came across an s3 bucket with my credit application details and I could delete it, I would probably do it and then report to their security team. It’s MY data security they’re being casual with. It occurs to me now that if I did that it would likely be a crime because of the harm to the company. The irony.