Former Amazon employee convicted of Capital One hack

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

An ex-Amazon Web Services (AWS) employee has been found guilty of multiple crimes in relation to one of the largest ever US data breaches.

According to a CNBC report, former AWS engineer Paige Thompson was found to have used her position within the firm to hack into Capital One’s database and steal sensitive information on more than 100 million people.

Using the alias “erratic”, she apparently built a tool that helped her search for misconfigured accounts on AWS. What she found was more than 30 such instances owned by Amazon clients, including Capital One. She then proceeded to mine that data and install cryptocurrency miners on some AWS servers.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Wire fraud, aggravated identity theft

The jury found Thompson guilty of seven federal crimes, including wire fraud, illegally accessing a protected computer, and damaging a protected computer. She was found not guilty of aggravated identity theft and access device fraud.

“She wanted data, she wanted money, and she wanted to brag,” Assistant United States Attorney Andrew Friedman said of Thompson, during closing arguments.

The sentencing is scheduled for September 15, and Thompson’s legal representative is yet to comment. Some of these crimes are punishable with up to 20 years of prison time

In mid-2019, financial giant Capital One revealed it suffered a major data breach, with around 106 million customers in the US and Canada having their personal details stolen, including names, addresses and phone numbers.

Around 140,000 US social security numbers and 80,000 linked bank account numbers are also thought to have been compromised, with about one million social insurance numbers belonging to Canadian credit card customers also affected.

Thompson was reported to police by a GitHub forum user after she apparently boasted of the attack online. 

Capital One was faced with a class-action lawsuit, following the breach, and agreed to settle by paying $190 million, as well as an additional $80 million in regulatory fines. 

Via CNBC

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
US soldier pleads guilty to AT&T and Verizon cyberattacks, linked to Snowflake data theft
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Stress
Time tracker tool spilled details on remote workers - millions of screenshots leaked
A person holding a virtual cloud in the palm of their hand.
Amazon EC2 instances could be under fire from whoAMI technique giving hackers code execution access
Representational image depecting cybersecurity protection
Top venture capital firm Insight Partners confirms it was hit by cyberattack
Data leak
Popular online bill paying site leaks data of thousands of users
Latest in Security
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
Latest in News
Panos Panay and Alexa Plus
Amazon's Panos Panay teases future Alexa+ devices from speakers to possible wearables
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Samsung Galaxy Z Fold 6
New rumors predict a foldable iPhone will launch next year – and cost almost twice as much as the iPhone 16 Pro Max
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments