Capital One Discloses Data Breach of 100 Million Credit Card Applications

News Capital One Data Breach Featured

Millions of people are reaching some financial relief, albeit limited, with the Equifax settlement that was reached last week. If you suffered a loss or spent money trying to protect your credit after your information was stolen, you’re getting something, even if it’s just a $125 check.

Yet, just days later, the news hit that there’s now been another data breach. This time it affects potential users of Capital One credit cards. You don’t even have to use one to be affected, as the data breach affected around100 million credit card applications.

Capital One Data Breach

You recorded on the credit card application all that personally identifiable information about you as the bank needs it to check your credit score and to also determine whether it’s financially wise to issue you a credit card. But now a hacker has your information from that application.

The FBI arrested Paige A. Thompson from the Settle area and charged her with computer fraud and abuse, according to court records. She is accused of accessing around 100 million credit card applications and taking Social Security numbers and bank account numbers.

While the Equifax data breach affected 147 million people, this breach is reaching similar numbers, making it one of the largest data breaches ever. Equifax last week reached a $700 million settlement over their breach.

“While I am grateful that the perpetrator has been caught, I am deeply sorry for what has happened,” said Capital One’s chairman and chief executive, Richard D. Fairbank.

“I sincerely apologize for the understandable worry this incident must be causing those affected, and I am committed to making it right.”

Capital One tried to reassure people and let them know not all information was stolen. No credit card numbers or log-in credentials were compromised, and most of the Social Security numbers weren’t either.

Thompson was arrested quickly in this case, mostly because she made the mistake of bragging about her windfall online with the username of “erratic.”

News Capital One Data Breach Woman

She “made statements on social media for evidencing the fact that she has information of Capital One and that she recognizes that she has acted illegally,” said FBI special agent Joel Martini in a criminal complaint.

Thompson wrote in one post, “I’ve basically strapped myself with a bomb vest, [expletive] dropped capitol ones [sic] dox and admitting it.”

According to court records, Thompson is suspected of “exfiltrating and stealing information, included credit card applications and other documents, from Capital One.” She was ordered to remain in jail until at least her detention hearing with is scheduled for Thursday, August 1.

The FBI complaint said that while some of the information, such as Social Security numbers, on the applications “has been tokenized or encrypted,” other information, including names, addresses, birth dates and credit history information has not been tokenized. The bank believes the data includes “likely tens of millions of applications and approximately 77,000 bank account numbers.”

On July 17 Capital One learned a person in an online discussion group was claiming to have taken large amounts of data from the company. Once the bank investigated, they were able to confirm the breach.

Using the Slack messaging service, Thompson listed the files she claimed she possessed. She followed this by saying, “I wanna get it off my server that’s why I’m archiving all of it … its all encrypted.”

Previously, she worked at a cloud computing company that provided data services to Capital One. The FBI suspects she “intended to disseminate data stolen from victim entities, starting with Capital One.”

Little to No Protection

It’s easy to feel there is little to no protection. Banks provide a lot of security, helping out the little guys who don’t have the technical known-ho to do so. Yet still, they are open to being hacked just as anyone else is. And $125 doesn’t seem like it will be enough to fix the wrong here, just like it wasn’t in the Equifax case either.

Do you feel more vulnerable now? Are you a Capital One client, or have you applied for one of their credit cards in the past? Let us know in the comments below.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.
When survivors near Lake Nyos woke on the morning of 22 August 1986, the cattle were dead in the fields, the birds had fallen out of the trees, and 1,746 of their neighbours were lying where they had stood the night before, with no fire, no flood, and no wound to explain it.
In October 2002, a Russian scientist named Dimitri Malashenkov stood up at a space conference in Houston and quietly explained that the dog Laika, whom the Soviet Union had publicly mourned as a heroic week-long orbiter in 1957, had actually died of heat and panic within about five hours of launch.