Capital One Hack
By Chris Eburne · Module IT
Over 106 million personal details were stolen from Capital One and published on the web. The suspected hacker had access to all data submitted to Capital One between 2005 and 2019.
What Happened
The Seattle-based suspect was arrested by the FBI at her home. The financial giant said the intruder exploited a configuration vulnerability, while prosecutors stated that a firewall misconfiguration permitted commands to reach and be executed by Capital One's cloud-based storage servers.
The attacker used a VPN service and the Tor anonymising network to illegally access the bank's cloud systems and download the private data. The misconfiguration has since been fixed.
The Lesson for Businesses
This is one of the most prominent examples of what can go wrong when cloud environments are not properly configured. Moving to the cloud does not mean you are automatically secure. Your security posture needs to be actively managed.
Key actions for businesses:
- Regularly audit cloud storage permissions and firewall configurations
- Ensure web application firewalls are correctly set up and tested
- Monitor for unusual access patterns
- Apply least-privilege principles to all cloud services
Module IT can conduct a cloud security review for your business. Get in touch to find out more.
Get expert IT insights in your inbox
Cyber security, AI readiness, VoIP migration — no fluff, just actionable intelligence for UK businesses.