2019 misconfigured firewall — AWS
Data compromised
Names, Addresses, Credit card numbers, Account numbers, Bank account details, Credit/financial data
Technical writeup
A misconfigured web application firewall on AWS allowed an attacker to access Capital One credit card application data. Names, addresses, credit scores, and fragments of bank account numbers were exfiltrated.
Root cause
Misconfigured WAF (SSRF) allowing access to AWS metadata and underlying data store.