Capital One hack may have been bigger than thought

(Image credit: Shutterstock)

The hacker behind the Capital One data breach may have also been responsible for attacks on multiple other companies, law forces have said.

Paige Thompson may have stolen data from more than 30 other organisations, according to US officials investigating the case after uncovering more evidence.

The information of around 106 million people who were either existing Capital One customers or new applicants in the US and Canada had their personal details stolen in the attack, with information such as names, addresses and phone numbers all at risk.

'Criminal conduct'

In new court documents revealed this week, US prosecutors said they were widening their investigation into Paige A. Thompson, a 33-year-old former software engineer, suspected of carrying out the attack.

Ex-Amazon worker Thompson was reported to police by a GitHub forum users after she apparently boasted of the attack online.

The other affected companies are unknown, but some reports have named the likes of Unicredit, Vodafone, Ford, Michigan State University, and the Ohio Department of Transportation among possible victims.

"The government's investigation over the last two weeks has revealed that Thompson's theft of Capital One's data was only one part of her criminal conduct," a memo from law officials said.

"The servers seized from Thompson's bedroom during the search of Thompson's residence, include not only data stolen from Capital One, but also multiple terabytes of data stolen by Thompson from more than 30 other companies, educational institutions, and other entities."

US prosecutors said the "data varies significantly in both type and amount," but, based on currently available information, "much of the data appears not to be data containing personal identifying information."

They added that the case against Thompson seems open-and-shut, stating, "the evidence that Thompson committed this crime is overwhelming."

In total, Capital One believes the breach affected approximately 100 million individuals in the US, as well as six million more in Canada. 

Around 140,000 US social security numbers and 80,000 linked bank account numbers are thought to be compromised, with about one million social insurance numbers belonging to Canadian credit card customers also affected.

Aside from names and dates of birth, the hacker also managed to obtain credit scores, limits, balances, payment history and contact information.

Via ZDNet

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog