{
  "id": "case-thompson-capital-one",
  "slug": "us-v-thompson-capital-one",
  "title": "U.S. v. Paige Thompson (Capital One AWS Cloud SSRF Breach)",
  "summary": "Former Amazon Web Services systems engineer convicted under the Computer Fraud and Abuse Act for exploiting a misconfigured open-source Web Application Firewall (WAF) using Server-Side Request Forgery (SSRF) to query AWS metadata services and steal over 100 million credit card applications from Capital One.",
  "case_number": "2:19-cr-00159",
  "court": "U.S. District Court for the Western District of Pennsylvania and Western District of Washington",
  "district": "W.D. Wash.",
  "country": "United States",
  "opened_at": "2019-08-28",
  "status": "sentenced",
  "victim_sector": "Financial Services, Cloud Computing",
  "victim_country": "United States",
  "loss_amount_usd": 270000000,
  "loss_amount_note": "Capital One agreed to pay an $80 million regulatory fine to the OCC and a $190 million class-action consumer settlement.",
  "first_seen_at": "2019-03-22T00:00:00Z",
  "last_updated_at": "2026-09-01T15:00:00Z",
  "actor_slug": "paige-thompson-erratic",
  "defendant_slugs": [
    "paige-thompson"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Thompson executed Server-Side Request Forgery (SSRF) requests against a misconfigured ModSecurity WAF running on an EC2 instance, instructing the server to query the local AWS instance metadata service at 169.254.169.254.",
      "evidence_locator": "Indictment \u00b6 8, Page 3",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Thompson",
      "source_url": "https://www.justice.gov/usao-wdwa/pr/former-seattle-tech-worker-convicted-wire-fraud-and-computer-intrusions",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "The metadata response yielded temporary security credentials for an IAM role named *PRIV_WA_SCAN*, which possessed excessive permissions to enumerate and download files from Capital One Amazon S3 buckets.",
      "evidence_locator": "Trial Exhibit 14, Criminal Complaint \u00b6 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Criminal Complaint: U.S. v. Thompson",
      "source_url": "https://www.justice.gov",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1567",
      "evidence_excerpt": "Using multithreaded cloud CLI commands, the defendant downloaded over 700 S3 buckets containing approximately 100 million credit card applications, Social Security numbers, and bank account details.",
      "evidence_locator": "Indictment \u00b6 11, Page 5",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov",
      "technique_name": "Exfiltration Over Web Service",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2019-08-28",
      "description": "Federal grand jury indicts Thompson on wire fraud and seven counts of computer intrusion."
    },
    {
      "event_type": "verdict",
      "event_date": "2022-06-17",
      "description": "Jury finds Thompson guilty of wire fraud, unauthorized access to a protected computer, and damaging a protected computer."
    },
    {
      "event_type": "sentencing",
      "event_date": "2022-10-04",
      "description": "Court sentences Thompson to time served and five years of supervised release."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity Web Application Firewall (WAF) hosted on an Amazon Web Services EC2 instance.",
    "blast_radius": "Over 100 million credit card applications, 140,000 Social Security numbers, and 80,000 linked bank account numbers exfiltrated from 700 Amazon S3 storage buckets. Capital One paid an $80 million regulatory fine and a $190 million class action settlement.",
    "kill_chain": [
      {
        "phase": "SSRF Exploitation",
        "title": "Metadata Service Credential Theft",
        "description": "Thompson sent crafted HTTP requests to the misconfigured WAF, tricking it into querying the AWS local metadata service (169.254.169.254) and returning temporary security credentials for an IAM role.",
        "technical_artifacts": [
          "SSRF vulnerability",
          "AWS EC2 Instance Metadata Service (IMDSv1)"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Privilege Abuse",
        "title": "Overprivileged IAM Role Enumeration",
        "description": "The stolen IAM role (*PRIV_WA_SCAN*) possessed excessive permissions allowing the attacker to list and read all files across Capital One's Amazon S3 object storage environment.",
        "technical_artifacts": [
          "AWS IAM role: PRIV_WA_SCAN",
          "aws s3 ls commands"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Automated Cloud Exfiltration",
        "title": "Mass S3 Bucket Download and Public Boasting",
        "description": "Using high-speed multithreaded cloud CLI scripts, Thompson downloaded over 700 buckets containing 100M+ customer applications to her personal server, then discussed the breach on Slack and posted scripts to GitHub.",
        "technical_artifacts": [
          "aws s3 sync scripts",
          "GitHub public repository commits"
        ],
        "mitre_technique_id": "T1567"
      }
    ],
    "defensive_takeaways": [
      "Enforce AWS Instance Metadata Service Version 2 (IMDSv2) across all EC2 instances to require session tokens and block SSRF attacks.",
      "Apply principle of least privilege to IAM roles, ensuring WAF instances cannot read customer databases or S3 storage.",
      "Deploy S3 Object Lock and real-time AWS CloudTrail alerts for anomalous bulk S3 GetObject API calls.",
      "Regularly audit cloud configurations against CIS AWS Foundations Benchmarks."
    ]
  }
}