Target Sector: Financial Services, Cloud Computing
Court filings, technical advisories, and enforcement actions documenting cyber intrusions against Financial Services, Cloud Computing organizations.
Key Facts
- 2 documented prosecution cases targeting the Financial Services, Cloud Computing sector.
- Cumulative reported financial losses exceed $540.0 million.
- Documented from federal indictments and SEC Form 8-K disclosures.
Documented Incidents
U.S. v. Paige Thompson (Capital One Cloud Breach)
Former Seattle cloud engineer who identified misconfigured web application firewalls to gain unauthorized access to Capital One's Amazon Web Services storage buckets, exfiltrating 106 million customer credit card applications.
U.S. v. Paige Thompson (Capital One AWS Cloud SSRF Breach)
Former Amazon Web Services systems engineer convicted under the Computer Fraud and Abuse Act for exploiting a misconfigured open-source Web Application Firewall (WAF) using Server-Side Request Forgery (SSRF) to query AWS metadata services and steal over 100 million credit card applications from Capital One.