Former Amazon employee convicted of Capital One hack

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

An ex-Amazon Web Services (AWS) employee has been found guilty of multiple crimes in relation to one of the largest ever US data breaches.

According to a CNBC report, former AWS engineer Paige Thompson was found to have used her position within the firm to hack into Capital One’s database and steal sensitive information on more than 100 million people.

Using the alias “erratic”, she apparently built a tool that helped her search for misconfigured accounts on AWS. What she found was more than 30 such instances owned by Amazon clients, including Capital One. She then proceeded to mine that data and install cryptocurrency miners on some AWS servers.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Wire fraud, aggravated identity theft

The jury found Thompson guilty of seven federal crimes, including wire fraud, illegally accessing a protected computer, and damaging a protected computer. She was found not guilty of aggravated identity theft and access device fraud.

“She wanted data, she wanted money, and she wanted to brag,” Assistant United States Attorney Andrew Friedman said of Thompson, during closing arguments.

The sentencing is scheduled for September 15, and Thompson’s legal representative is yet to comment. Some of these crimes are punishable with up to 20 years of prison time

In mid-2019, financial giant Capital One revealed it suffered a major data breach, with around 106 million customers in the US and Canada having their personal details stolen, including names, addresses and phone numbers.

Around 140,000 US social security numbers and 80,000 linked bank account numbers are also thought to have been compromised, with about one million social insurance numbers belonging to Canadian credit card customers also affected.

Thompson was reported to police by a GitHub forum user after she apparently boasted of the attack online. 

Capital One was faced with a class-action lawsuit, following the breach, and agreed to settle by paying $190 million, as well as an additional $80 million in regulatory fines. 

Via CNBC

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
US soldier pleads guilty to AT&T and Verizon cyberattacks, linked to Snowflake data theft
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Stress
Time tracker tool spilled details on remote workers - millions of screenshots leaked
A person holding a virtual cloud in the palm of their hand.
Amazon EC2 instances could be under fire from whoAMI technique giving hackers code execution access
Representational image depecting cybersecurity protection
Top venture capital firm Insight Partners confirms it was hit by cyberattack
Data leak
Popular online bill paying site leaks data of thousands of users
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
Seth Milchick and Kier Eagan's animatronic speaking in Severance season 2 episode 10
Apple TV+ announces Severance has been renewed for season 3 after that devastating finale