Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

1–10 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#4
> Capital One Financial Corp. lost data from as many as tens of millions of credit card applications after a Seattle woman hacked into a cloud-computing company server

> The cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers

I can’t tell whether the company virtual server got hacked or whether the cloud provider was who got breached. Hopefully just the vm

Re: Capital One Says Breach Hit 100M Individuals in U.S

#5
post #4

> Capital One Financial Corp. lost data from as many as tens of millions of credit card applications after a Seattle woman hacked into a cloud-computing company server > The cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers I can’t tell whether the company virtual server got hacked or whether the cloud provider was who got breached. Hopefully just the vm

They're on AWS so I doubt the cloud provider got hacked, it would have been a much bigger news story. https://aws.amazon.com/solutions/case-studies/innovators/cap...

Re: Capital One Says Breach Hit 100M Individuals in U.S

#6
> hacked into a cloud-computing company server, federal prosecutors in Seattle said

> the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers.

Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#9

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

Given that they're on AWS and "The intrusion occurred through a misconfigured web application firewall that enabled access to the data" thats what im betting too.
Post reply on HN