Back to Blog
Cyber Security 4 min read23 Apr 2026

Capital One Hack

By Chris Eburne · Module IT

Image unavailable
Share:

Over 106 million personal details were stolen from Capital One and published on the web. The suspected hacker had access to all data submitted to Capital One between 2005 and 2019.

What Happened

The Seattle-based suspect was arrested by the FBI at her home. The financial giant said the intruder exploited a configuration vulnerability, while prosecutors stated that a firewall misconfiguration permitted commands to reach and be executed by Capital One's cloud-based storage servers.

The attacker used a VPN service and the Tor anonymising network to illegally access the bank's cloud systems and download the private data. The misconfiguration has since been fixed.

The Lesson for Businesses

This is one of the most prominent examples of what can go wrong when cloud environments are not properly configured. Moving to the cloud does not mean you are automatically secure. Your security posture needs to be actively managed.

Key actions for businesses:

  • Regularly audit cloud storage permissions and firewall configurations
  • Ensure web application firewalls are correctly set up and tested
  • Monitor for unusual access patterns
  • Apply least-privilege principles to all cloud services

Module IT can conduct a cloud security review for your business. Get in touch to find out more.

// Stay Informed

Get expert IT insights in your inbox

Cyber security, AI readiness, VoIP migration — no fluff, just actionable intelligence for UK businesses.

Share:

We use cookies to improve your experience and analyse site traffic. By continuing, you agree to our use of cookies in accordance with UK GDPR. Learn more