Federal Criminal Record sentenced
U.S. v. Paige Thompson (Capital One AWS Cloud SSRF Breach)

Former Amazon Web Services systems engineer convicted under the Computer Fraud and Abuse Act for exploiting a misconfigured open-source Web Application Firewall (WAF) using Server-Side Request Forgery (SSRF) to query AWS metadata services and steal over 100 million credit card applications from Capital One.

Loss Amount $270M
Techniques 3 Mapped
Threat Actor Individual