Capital One ordered to pay $80 million penalty for its role in a 2019 data breach


Capital One will pay an $80 million civil penalty for its role in a 2019 security breach that exposed the personal data of more than 100 million customers, The Wall Street Journal reported. In a scathing report on its investigation into the breach, the Office of the Comptroller of Currency, part of the US Treasury. said Capital One was aware its security practices were woefully insufficient, and that the company’s board of directors “failed to take effective actions to hold management accountable.”
The breach happened in March and April of 2019, but Capital One was apparently not aware of the problem until mid-July. That’s when someone tipped the company to a public GitHub page where private Capital One data was available. That led investigators to former Amazon cloud employee Paige Thompson, who was charged with wire fraud and computer fraud. Authorities say Thompson was able to exploit a “configuration vulnerability” to extract the Capital One customers’ information and post it to message boards. She pleaded not guilty to the charges and her trial is scheduled for next year.
“The OCC took these actions based on the bank’s failure to establish effective risk assessment processes prior to migrating significant information technology operations to the public cloud environment and the bank’s failure to correct the deficiencies in a timely manner,” the OCC said in a statement announcing the penalty.
As part of a consent order from OCC, Capital One must establish a compliance committee by the end of August, which will meet quarterly beginning in October and provide regular updates. The company is required to create an action plan to detail what steps it’s taking to improve security.
A Capital One spokesperson said in an email to The Verge that controls the company put in place before last year’s incident “enabled us to secure our data before any customer information could be used or disseminated and helped authorities quickly arrest the hacker.” Since the incident, the spokesperson added, the company has “invested significant additional resources into further strengthening our cyber defenses, and have made substantial progress in addressing the requirements of these orders.”
The penalty will be paid to the Treasury department.
UPDATE August 8th 10:38AM ET: Adds statement from Capital One spokesperson
Capital One will pay an $80 million civil penalty for its role in a 2019 security breach that exposed the personal data of more than 100 million customers, The Wall Street Journal reported. In a scathing report on its investigation into the breach, the Office of the Comptroller of Currency,…
Recent Posts
- Apple will let parents share their kids’ ages to limit app access
- Perplexity’s voice mode gets a futuristic makeover on your iPhone
- OpenAI announces GPT-4.5, warns it’s not a frontier AI model
- The 5 best mechanical keyboards for 2025
- OpenAI Launches GPT-4.5 for ChatGPT—It’s Huge and Compute-Intensive
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010