← Capital One

2019 misconfigured firewall — AWS

2019 100.0M records affected Share on X

Data compromised

Names, Addresses, Credit card numbers, Account numbers, Bank account details, Credit/financial data

Technical writeup

A misconfigured web application firewall on AWS allowed an attacker to access Capital One credit card application data. Names, addresses, credit scores, and fragments of bank account numbers were exfiltrated.

Root cause

Misconfigured WAF (SSRF) allowing access to AWS metadata and underlying data store.

References