Live data from Hacker News

Capital One Says Breach Hit 100M Individuals in U.S

bloomberg.com

21–30 of 319 posts

Re: Capital One Says Breach Hit 100M Individuals in U.S

#22

If I came across an s3 bucket with my credit application details and I could delete it, I would probably do it and then report to their security team. It’s MY data security they’re being casual with. It occurs to me now that if I did that it would likely be a crime because of the harm to the company. The irony.

Who cares if it has your data in it or not. Just report it to authorities and the guy who runs haveibeenpwned.

Plus what are you going to do with credit card applications anyway? Sell them to a marketing company with some phony story? Or the 'sell them on the darknet to fraudsters in Russia' angle? Unless you're already involved in some dirty business already this isn't very valuable.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#23

Earlier quoted context omitted.

DOJ press release: https://www.justice.gov/usao-wdwa/pr/seattle-tech-worker-arr... """ A former Seattle technology company software engineer was arrested today on a criminal complaint charging computer fraud and abuse for an intrusion on the stored data of Capital One Financial Corporation, announced U.S. Attorney Brian T. Moran. PAIGE A. THOMPSON a/k/a erratic, 33, made her initial appearance in U.S. District Court…

intrusion occurred through a misconfigured web application firewall The affidavit states “exfiltrating and stealing information, including credit card applications and other documents”. She used a particular role to exfill from an S3 bucket. Not sure how she got the creds for the role she used to execute List Buckets, etc... Affidavit shows the accused was an employee at the unnamed cloud vendor (clearly AWS at this…

Either that or an open MongoDB with default credentials. Again.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#25
post #18

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

If the Seattle "Paige T." is the person with a public Linkedin profile, their recent job history includes "Systems Engineer" at AWS. That could be connected with the breach.

Woah man.

You could be costing some unfortunate woman her job here man. Kind of like when that lady cop broke into that black guy's apartment and blew him away. Then all these people on social media started posting pictures of his coworker on social media and almost cost the woman her position at PwC.

We should try to be a little more responsible than that.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#26

I downloaded the indictment (edit: complaint, not indictment) from PACER: https://www.dropbox.com/s/z7u5rxcdajuvw6t/19718675504.pdf?dl...

It's a wild ride. Who hacks in via Tor and then posts the data to a GitLab account under their own name?

Re: Capital One Says Breach Hit 100M Individuals in U.S

#27
post #3

Anyone have a copy of the complaint handy? I'd love to read the Government's allegations in more detail. (Edited: complaint, not indictment.)

DOJ press release: https://www.justice.gov/usao-wdwa/pr/seattle-tech-worker-arr... """ A former Seattle technology company software engineer was arrested today on a criminal complaint charging computer fraud and abuse for an intrusion on the stored data of Capital One Financial Corporation, announced U.S. Attorney Brian T. Moran. PAIGE A. THOMPSON a/k/a erratic, 33, made her initial appearance in U.S. District Court…

Why, exactly, did she "post[ed] on the information sharing site GitHub about her theft of information from the servers storing Capital One data" ?

That seems... unwise. Anyone have a pointer to the github post? Would be interesting to see if it was a "Haha! Look what I did!" kind of thing, or a "Crap, CapOne has an open S3 bucket" kind of post.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#28

> hacked into a cloud-computing company server, federal prosecutors in Seattle said > the cloud-computing company, on whose servers Capital One rented space, wasn’t identified in court papers. Does this feel like it was just an S3 bucket with permissions set incorrectly? I've come across sensitive documents in S3 buckets with a well crafted google search.

The court filing directly says "s3", so yeah, it's Amazon.

Re: Capital One Says Breach Hit 100M Individuals in U.S

#29
post #25
post #18

Earlier quoted context omitted.

If the Seattle "Paige T." is the person with a public Linkedin profile, their recent job history includes "Systems Engineer" at AWS. That could be connected with the breach.

Woah man. You could be costing some unfortunate woman her job here man. Kind of like when that lady cop broke into that black guy's apartment and blew him away. Then all these people on social media started posting pictures of his coworker on social media and almost cost the woman her position at PwC. We should try to be a little more responsible than that.

Wasn't her name that the parent comment referenced originally posted in the news article? If that's the case, I would blame the news article and not the parent. Especially since they said "could" and not "yep, that's her".

Re: Capital One Says Breach Hit 100M Individuals in U.S

#30
post #3

Anyone have a copy of the complaint handy? I'd love to read the Government's allegations in more detail. (Edited: complaint, not indictment.)

DOJ press release: https://www.justice.gov/usao-wdwa/pr/seattle-tech-worker-arr... """ A former Seattle technology company software engineer was arrested today on a criminal complaint charging computer fraud and abuse for an intrusion on the stored data of Capital One Financial Corporation, announced U.S. Attorney Brian T. Moran. PAIGE A. THOMPSON a/k/a erratic, 33, made her initial appearance in U.S. District Court…

"ORDER APPOINTING FEDERAL PUBLIC DEFENDER appointing Christopher Sanders for Paige A Thompson. On the basis of the defendant's sworn financial statement, the court finds that he/she is financially unable to retain counsel."

Oh, dear.

Post reply on HN