Space News from SpaceDaily.com
US woman charged in massive Capital One data breach
Los Angeles, July 30 (AFP) Jul 30, 2019
A tech engineer in the western US state of Washington was arrested Monday on charges of stealing sensitive data from millions of credit card applications at financial heavyweight Capital One.

Paige Thompson, 33, a former Seattle technology company software engineer, was nabbed by FBI agents after she boasted about the data theft -- one of the biggest to hit a financial services company -- on the information sharing site GitHub, authorities said.

"The intrusion occurred through a misconfigured web application firewall that enabled access to the data," a statement by the US attorney's office in Washington said. "On July 17, 2019, a GitHub user who saw the post alerted Capital One to the possibility it had suffered a data theft."

It said the Virginia-based bank that specializes in credit cards contacted the FBI after confirming the data theft, which took place between March 12 and July 17 of this year.

"According to Capital One, the data includes data regarding large numbers of (credit card) applications, likely tens of millions of applications," according to the complaint.

In a statement, Capital One said the hack affected 100 million individuals in the United States and six million in Canada.

"Importantly, no credit card account numbers or log-in credentials were compromised and over 99 percent of social security numbers were not compromised," the bank said.


- Up to five years in prison -


Thompson, who used the alias "erratic" in online conversations, allegedly posted several times about the theft on GitHub and on social media.

One posting on a Twitter account with the user name "erratic" read: "I've basically strapped myself with a bomb vest, fucking dropping capital ones dox and admitting it," according to the complaint.

Authorities said electronic storage devices containing a copy of the stolen data were recovered at her residence on Monday.

Capital One said although some of the information in the applications stolen, such as social security numbers, is encrypted or tokenized, other information such as names, addresses, dates of birth and credit card history was not secured.

Capital One said it expects the breach to generate incremental costs of approximately $100 to $150 million in 2019.

"While I am grateful that the perpetrator has been caught, I am deeply sorry for what has happened," Richard D. Fairbank, the company's chairman and CEO, said in a statement. "I sincerely apologize for the understandable worry this incident must be causing those affected and I am committed to making it right."

Thompson faces up to five years in prison and a $250,000 fine if convicted of computer fraud.

She was ordered held in jail Monday pending a detention hearing later this week.


ADVERTISEMENT




Space News from SpaceDaily.com
Fly through Webbs cosmic vistas celebrates four years of James Webb discoveries
China harnesses nationwide system to drive spaceflight and satellite navigation advances
How an Earnings Calendar Improves Your Investment Decisions

24/7 Energy News Coverage
Molecular catalyst switches between hydrogen and oxygen production
Project Pele microreactor reaches key milestone with first TRISO fuel delivery
Heat limits on communication in computers

Military Space News, Nuclear Weapons, Missile Defense
Terran Orbital to build satellite buses for SDA Tranche 3 Tracking Layer
UAV swarm algorithm boosts spectrum resilience in contested airspace
Spatiotemporal resilience model targets IoT unmanned fleets

24/7 News Coverage
NASA Earth science faces rollback as Mission to Planet Earth era winds down
OPERA satellite data sharpens US crop and water management
Alen Space begins SATMAR satellite validation over Bay of Algeciras


All rights reserved. Copyright Agence France-Presse. Sections of the information displayed on this page (dispatches, photographs, logos) are protected by intellectual property rights owned by Agence France-Presse. As a consequence, you may not copy, reproduce, modify, transmit, publish, display or in any way commercially exploit any of the content of this section without the prior written consent of Agence France-Presse.