Author Topic: Why the Capital One breach is unlike any other major hack  (Read 794 times)

0 Members and 1 Guest are viewing this topic.

Offline corbe

  • Hero Member
  • *****
  • Posts: 38,431
Why the Capital One breach is unlike any other major hack

Kate Fazzini
 
3 hrs ago

 
Capital One is dealing with what will likely be one of the most important breaches of the year.
 
The incident involved theft of more than 100 million customer records, 140,000 Social Security numbers and 80,000 linked bank details of Capital One customers, allegedly stolen by a single insider, according to court filings in Seattle.

The details set it apart from breaches of companies like Equifax and Marriott, which were attacked from the outside by criminals with a nation-state connection. It's also different from the spate of ransomware attacks against major U.S. cities, which were likely committed by groups of individuals outside the U.S.

Instead, according to the indictment of Paige Thompson, she was able to exploit a loophole in a Capital One cloud server's firewall to gain access to the information.

Thompson had several social media accounts listing experience as an engineer working for Amazon. Even if Thompson was employed at Amazon, it may not have been a factor in the incident.

Amazon Web Services "was not compromised in any way and functioned as designed," Amazon said in a statement, adding that the reason for the breach was a misconfiguration of firewall settings managed on the cloud server by Capital One, not a vulnerability in the cloud server itself.

The incident, which is still unraveling, will bring up major issues facing the biggest tech companies, cloud firms and banks, namely how to control who has access to sensitive consumer data and detect insiders who may go rogue.

An unlikely scenario


<..snip..>

http://www.msn.com/en-us/money/companies/why-the-capital-one-breach-is-unlike-any-other-major-hack/ar-AAF4qVM?ocid=ientp
No government in the 12,000 years of modern mankind history has led its people into anything but the history books with a simple lesson, don't let this happen to you.

Offline IsailedawayfromFR

  • Hero Member
  • *****
  • Posts: 18,746
Re: Why the Capital One breach is unlike any other major hack
« Reply #1 on: July 31, 2019, 12:18:31 pm »
Do not use Capital One but get mailed incessantly offers to get their card.

Am wondering if I am also affected as Capital One obtained my financial information from the credit agencies to make the pitches to me?
No punishment, in my opinion, is too great, for the man who can build his greatness upon his country's ruin~  George Washington

Bill Cipher

  • Guest
Re: Why the Capital One breach is unlike any other major hack
« Reply #2 on: July 31, 2019, 04:52:45 pm »
Do not use Capital One but get mailed incessantly offers to get their card.

Am wondering if I am also affected as Capital One obtained my financial information from the credit agencies to make the pitches to me?

Doubtful that anything personal was compromised just because Capital One got info on you from the credit agencies. 

My understanding of the way that works is that the company seeking the info is only allowed to ask the credit agency for names and addresses of individuals who meet certain broad-based criteria, like having no more than a certain number of other accounts, or less than a certain number of delinquent payments over a given time period.  The agency then gives the requesting company the contact info of thousands of hundreds of thousands of individuals. 

Offline rustynail

  • Hero Member
  • *****
  • Posts: 6,147
Re: Why the Capital One breach is unlike any other major hack
« Reply #3 on: July 31, 2019, 05:20:32 pm »
TransPower!

Offline IsailedawayfromFR

  • Hero Member
  • *****
  • Posts: 18,746
Re: Why the Capital One breach is unlike any other major hack
« Reply #4 on: July 31, 2019, 05:39:16 pm »
Doubtful that anything personal was compromised just because Capital One got info on you from the credit agencies. 

My understanding of the way that works is that the company seeking the info is only allowed to ask the credit agency for names and addresses of individuals who meet certain broad-based criteria, like having no more than a certain number of other accounts, or less than a certain number of delinquent payments over a given time period.  The agency then gives the requesting company the contact info of thousands of hundreds of thousands of individuals.
Thanks.  Never knew that
No punishment, in my opinion, is too great, for the man who can build his greatness upon his country's ruin~  George Washington