← Blog

Capital One Data Breaches: Full Timeline Through 2026

Share on X

People search Capital One data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 8 Capital One-linked incidents, with headline counts up to 106M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why Capital One breach history matters

Capital One operates in Finance (United States). Across indexed rows, recurring themes include cloud and database misconfiguration. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2019 — AWS

Cataloged incident. A misconfigured web application firewall on AWS allowed an attacker to access Capital One credit card application data. Names, addresses, credit scores, and fragments of bank account numbers were exfiltrated. Exposed categories include Names, Addresses, Credit card numbers, Account numbers, Bank account details, Credit/financial data. BreachHistory cites approximately 100M+ affected records in this row. See the lrbg and canonical BreachHistory entry.

2019 — — 106M records

Cataloged incident. Unsecured S3. 106M records. Exposed categories include Names, emails, addresses, and other PII. BreachHistory cites approximately 1K+ affected records in this row. See the capital-one2019 and canonical BreachHistory entry.

2019 — — Capital One: Hacking, 10,000,000 records

Cataloged incident. The massive data breach included personal information from credit card applications over a 14-year period. A former Amazon employee, Paige Thompson, 36, was found guilty of wire fraud. Exposed categories include Personal and demographic data. BreachHistory cites approximately 10M+ affected records in this row. See the capital-one2019-iib and canonical BreachHistory entry.

2019 — — Capital One: Poor security / misconfiguration, 106,000,000 records

Cataloged incident. Data breach reported. financial organization. Method: unsecured S3 bucket. Source: Wikipedia List of data breaches. Exposed categories include Personal and demographic data. BreachHistory cites approximately 106M+ affected records in this row. See the capital-one2019-106000000-wiki2 and canonical BreachHistory entry.

2017 — — Capital One: WHAT HAPPENED As we have discussed with you…

Cataloged incident. WHAT HAPPENED As we have discussed with you recently, someone made or attempted to make unauthorized transactions on your Capital One account(s) by logging in with your username and password, which we believe were stolen from one of these websites. This is a follow-up letter to provide you with notice of what happened and ensure all of your questions have been addressed.WHAT INFORMATION WAS INVOLVED We believe that , the fraudster had access to your Capital One account information, which may inc Exposed categories include Personal information. No attested victim count is published for this row yet. See the capital-one2017 and canonical BreachHistory entry.

2014 — — Capital One: Capital One has sent notification to customers…

Cataloged incident. Capital One has sent notification to customers regarding a possible breach to their personal information. They discovered that a former employee of the company may have improperly accessed customer accounts, which could have been linked to unauthorized transactions. The information accessed included names, account numbers, SOcial SEcurity numbers, payment information and other account information. The credit card company has notified law enforcement of the breach.The company is also offering one Exposed categories include Personal information. No attested victim count is published for this row yet. See the capital-one2014 and canonical BreachHistory entry.

2013 — — Capital One: Two men face charges of conspiracy to commit bank…

Cataloged incident. Two men face charges of conspiracy to commit bank fraud, conspiracy to commit access device fraud, and aggravated identity theft after being indicted for attaching skimming devices to ATMs in New York, New Jersey, Illinois, and Wisconsin.  At least nine other people are believed to have participated in the bank fraud scheme.  Over 6,000 J.P. Morgan Chase and Capital One bank accounts were defrauded for over $3 million. Exposed categories include Personal information. BreachHistory cites approximately 6K+ affected records in this row. See the capital-one2013 and canonical BreachHistory entry.

2012 — — Capital One: A former employee pled guilty to conspiracy to…

Cataloged incident. A former employee pled guilty to conspiracy to commit bank fraud and aggravated identity theft.  The former employee received $3,000 for his role in the conspiracy and his co-conspirators fraudulently made $84,169.37 from customers. Exposed categories include Personal information. No attested victim count is published for this row yet. See the capital-one2012 and canonical BreachHistory entry.

Patterns and analysis

  • Cloud and database misconfiguration — appears across multiple Capital One catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Bookmark the Capital One company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/capital-one · Latest: lrbg.

Sources: BreachHistory catalog (8 rows for Capital One), company and regulator disclosures cited in individual breach records.