Capital One Says Data Breach Affected 100 Million Customers; Suspect Charged - NBC Bay Area
NBC Bay Area Responds Archive

NBC Bay Area Responds Archive

Capital One Says Data Breach Affected 100 Million Customers; Suspect Charged

Major Credit Card issuer says it fixed vulnerability; one person arrested



    More Than 100 Million Affected by Capital One Breach

    Capital One says a hacker got access to the personal information of over 100 million individuals applying for credit.

    (Published Monday, July 29, 2019)

    What to Know

    • Capital One says approximately 100 million customers are affected by a data breach

    • The credit card issuer says a hacker accessed personal data including addresses, dates of birth, and about 140,000 Social Security Numbers

    • Reports say federal authorities arrested a Seattle woman for the data breach

    Capital One Financial announced late Monday it had learned of a data breach that it says involves the personal information of more than 100 million customers, as federal authorities arrested a suspected hacker in the case.

    Paige A. Thompson — who also goes by the handle "erratic" — was charged with a single count of computer fraud and abuse in U.S. District Court in Seattle. Thompson made an initial appearance in court and was ordered to remain in custody pending a detention hearing Thursday.

    The hacker got information including credit scores and balances plus the Social Security numbers of about 140,000 customers, the bank said. 

    In a statement to news media, the credit card giant said it learned of the problem on July 19, and acted quickly to prevent further exploitation.

    Which Airlines and Airports Are Delayed the Most?

    [NATL] Which Airlines and Airports Are Delayed the Most?

    Data from the Bureau of Transportation Statistics reveal which airlines and airports have had the most delays from January to August, 2019. They also show which carriers and airports have done a great job getting you to your destination on time.

    (Published Tuesday, Nov. 12, 2019)

    "Capital One immediately fixed the configuration vulnerability that this individual exploited and promptly began working with federal law enforcement," the company said in its statement. "The FBI has arrested the person responsible and that person is in custody. Based on our analysis to date, we believe it is unlikely that the information was used for fraud or disseminated by this individual. However, we will continue to investigate."

    The FBI raided Thompson's residence Monday and seized digital devices. An initial search turned up files that referenced Capital One and "other entities that may have been targets of attempted or actual network intrusions."

    A public defender appointed to represent Thompson did not immediately return an email seeking comment.

    The company said most of the stolen information was taken from credit card applications filed by individuals and small business owners between 2005 and 2019. It said the stolen data includes names, addresses, phone numbers, dates of birth, and income. Capital One also said about 140,000 customers' Social Security Numbers were accessed, along with 80,000 linked bank account numbers.

    According to the FBI complaint, someone emailed the bank two days before that notifying it that leaked data had appeared on the code-hosting site GitHub, which is owned by Microsoft.

    And a month before that, the FBI said, a Twitter user who went by "erratic" sent another user direct messages warning about distributing the bank's data, including names, birthdates and Social Security numbers. That user later reported the message to Capital One.

    AP Probe: Aging US Dams Pose Risk to Thousands

    [NATL] AP Probe: Aging US Dams Pose Risk to Thousands

    An Associated Press investigation has found that thousands of people in the U.S. may be at risk from aging dams that are in poor condition. The two-year investigation identified 1,688 'high hazard' dams in 44 states and Puerto Rico.

    (Published Monday, Nov. 11, 2019)

    "Ive basically strapped myself with a bomb vest, (expletive) dropping capitol ones dox and admitting it," one said. "I wanna distribute those buckets i think first."

    Capital One said it believes it is unlikely that the information was used for fraud, but it will continue to investigate. The data breach affected about 100 million people in the U.S. and 6 million in Canada.

    The company will directly notify affected customers of the breach, and offer free credit monitoring and identity protection.

    A website was established for customers with questions or concerns, which can be found here:

    Get the latest from NBC Bay Area anywhere, anytime
    • Download the App

      Available for IOS and Android