Capital One Announces Data Security Incident
press.capitalone.com
Capital One Announces Data Security Incident
1–7 of 7 posts
Re: Capital One Announces Data Security Incident
#2In other words, someone didn't put a password on their S3 database exposed to the internet...
Re: Capital One Announces Data Security Incident
#3> We believe that a highly sophisticated individual was able to exploit a specific configuration vulnerability in our infrastructure. When this was discovered, we immediately addressed the configuration vulnerability and verified there are no other instances in our environment. In other words, someone didn't put a password on their S3 database exposed to the internet...
Re: Capital One Announces Data Security Incident
#4> We believe that a highly sophisticated individual was able to exploit a specific configuration vulnerability in our infrastructure. When this was discovered, we immediately addressed the configuration vulnerability and verified there are no other instances in our environment. In other words, someone didn't put a password on their S3 database exposed to the internet...
From reading news sites they were compromised by an Amazon employee, exploiting a bad WAF role.
Re: Capital One Announces Data Security Incident
#5> We believe that a highly sophisticated individual was able to exploit a specific configuration vulnerability in our infrastructure. When this was discovered, we immediately addressed the configuration vulnerability and verified there are no other instances in our environment. In other words, someone didn't put a password on their S3 database exposed to the internet...
Re: Capital One Announces Data Security Incident
#6> We believe that a highly sophisticated individual was able to exploit a specific configuration vulnerability in our infrastructure. When this was discovered, we immediately addressed the configuration vulnerability and verified there are no other instances in our environment. In other words, someone didn't put a password on their S3 database exposed to the internet...
Re: Capital One Announces Data Security Incident
#7This kind of double speak should double their fine.