IOTW: Capital One hacker given probation following cyber attack

A former Amazon software engineer was found guilty of seven charges

Add bookmark
Capital One hacker given probation following cyber attack

Paige Thompson, a former Amazon software engineer known by the online handle ‘erratic’ was sentenced to time served and five years’ probation for seven federal crimes. Thompson’s location and personal computer will also be monitored. 

The sentencing was related to her hacks into a number of cloud accounts for both individuals and companies, including the bank Capital One. During the hacks, Thompson stole data and computer power. At the trial, she was found guilty of five counts of unauthorized access to a protected computer, damaging a protected computer and wire fraud.

US Attorney Nick Brown said in a release that he was “very disappointed” in the sentencing, commenting that “this is not what justice looks like”.

He continued, saying: “Her cybercrimes created anxiety for millions of people who are justifiably concerned about their private information. This conduct deserves a more significant sanction.”

At the sentence hearing, US District Judge Robert Lasnik said that jail time would be “particularly difficult” for Thompson as she is transgender and suffers from mental health issues.

A hearing was scheduled for December 1 of this year to determine how much Thompson must pay in restitution to her victims.

What happened in the Captial One hack?

On July 19, 2019, Capital One alerted the public that an “outside individual” had gained unauthorized access and obtained the personal information of a number of Capital One customers who had either applied for or had a Capital One credit card.

During the hack, around one million Social Insurance numbers, 140,000 Social Security numbers and 80,000 linked bank account details were accessed. Other information including names, addresses, zip codes, phone numbers, email addresses, dates of birth and self-reported income were accessed.

In a statement, Capital One said it had “immediately fixed the issue” and began working with law enforcement, with the individual responsible being captured by the FBI.

Overall, the data breach affected 106 million people and did US$250 million worth of damage.

Despite the government saying that it “believe[d] the data has been recovered and that there is no evidence the data was used for fraud or shared by this individual”, Capital One still faced a class action lawsuit. The lawsuit saw Capital One establish a settlement fund of US$190 million for those affected by the cyber-attack.

How was Thompson involved in the hack? 

Using a tool she built, Thompson would scan cloud-based storage system Amazon Web Services to detect misconfigured accounts. Once these accounts were found, Thompson would then hack into the accounts and download the data held in the account. Using this method, she was able to hack into and download the data of more than 30 entities, including the Capital One bank. Thompson also used her unauthorized access to plant crypto mining software into unknowing user’s accounts, with the income of said software going directly to her online wallet.  

Thompson was arrested in July 2019 following an alert to the FBI by financial company Capital One regarding her hacking and was found guilty in June 2022.

Thompson shared information about the hacks via SMS and posts on online forums. The posts and texts were then used as evidence against her in court.

Her crimes were described by the prosecution as “fully intentional and grounded in spite, revenge, and willful disregard for the law”, with Thompson herself described as “exhibit[ing] a smug sense of superiority and outright glee while committing these crimes…motivated to make money at other people’s expense, to prove she was smarter than the people she hacked and to earn bragging rights in the hacking community”. 


Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":1,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":0,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"6335baa36e659145b108542e","name":"IOTW: Everything we know about the Optus data breach","description":"A full timeline of the Optus hack, breach and its impact on Australia","file":null,"url":"\/attacks\/news\/iotw-everything-we-know-about-the-optus-data-breach"},{"id":"632dbdc14b502166bf7f1947","name":"IOTW: Hacker allegedly hits both Uber and Rockstar","description":"A hacker has claimed they are responsible for hacking into both companies\u2019 servers","file":null,"url":"\/attacks\/news\/iotw-hacker-allegedly-hits-both-uber-and-rockstar"},{"id":"631225e4e3ff2019e254d296","name":"IOTW: FBI to investigate Montenegro cyber-attacks","description":"The cyber-attacks levelled against Montenegro have caused disruption to public and government services","file":null,"url":"\/attacks\/news\/iotw-fbi-to-investigate-montenegro-cyber-attacks"},{"id":"63074bdec434081b1a783deb","name":"IOTW: Plex urges customers to change passwords following data breach","description":"Streaming service Plex has requested all users reset their passwords following a data breach","file":null,"url":"\/attacks\/news\/iotw-plex-urges-customers-to-change-passwords-following-data-breach"},{"id":"62fb8a8c16bbef6fc15b4af2","name":"IOTW: Signal users directly targeted in Twilio phishing attack","description":"Phishing attack on Twilio targets almost 2,000 Signal users","file":null,"url":"\/attacks\/news\/iotw-signal-users-directly-targeted-in-twilio-phishing-attack"}],"featured_content_portal_embedded":null}" >