Capital One: Convicted techie got in via 'misconfigured' AWS buckets
- Reference: 1655731945
- News link: https://www.theregister.co.uk/2022/06/20/captial_one_wire_fraud/
- Source link:
[1]The conviction follows the infamous [2]2019 hack of Capital One in which personal information of more than 100 million US and Canadian credit card applicants were swiped from the financial giant's misconfigured cloud-based storage.
Paige Thompson (aka "erratic") was arrested in July 2019 after data was leaked between March and July of that year. The data was submitted by credit card hopefuls between 2005 and early 2019, and Thompson was able to get into Capital One's AWS storage thanks to a "misconfigured web application firewall."
[3]
According to the original July 2019 complaint
[4]PDF
, Capital One received an email to its responsible disclosure address stating: "There appears to be some leaked s3 data of yours in someone's github /gist."[5]
[6]
The complaint added: "Capital One determined that the April 21 file contained code for three commands, as well as a list of more than 700 folders or buckets of data."
Capital One then confirmed that they "matched the actual names of folders or buckets of data used by Capital One for data stored at the cloud company."
[7]
According to the US Attorney's office, Thompson used a tool to scan AWS accounts in search of misconfigurations. She then used the results to siphon data from more than 30 entities, including Capital One. "With some of her illegal access," wrote the office, "she planted cryptocurrency mining software on new servers with the income from the mining going to her online wallet."
Evidence from Thompson's own words in texts and online chats was used in the seven-day jury trial. The jury took 10 hours to come up with a verdict: guilty of wire fraud and five counts of unauthorized access to a protected computer and damaging a protected computer. Thompson was found not guilty of aggravated identity theft or access device fraud.
Sentencing is due on September 15, 2022.
[8]Jeff Bezos feels a tap on the shoulder. Ahem, Mr Amazon, care to explain how Capital One's AWS S3 buckets got hacked?
[9]Class-action sueball flung at Capital One and GitHub over theft of 106 million folks' details
[10]Watch as 10 cops with guns and military camo storm suspected Capital One hacker's house…
[11]Capital One gets Capital Done: Hacker swipes personal info on 106 million US, Canadian credit card applicants
As for Capital One, [12]it was memorably slapped with a $80 million fine and settled customer lawsuits for $190 million following the leak. The Office of the Comptroller of the Currency (OCC), an independent bureau of the US Department of Treasury, took the Virginia-based bank to task over its shoddy security practices and applied for a cease and desist order against Capital One, forbidding it from "engaging in unsafe or unsound practices, including those relating to information security."
Quite an expensive misconfiguration, all told.
[13]
"Ms Thompson used her hacking skills to steal the personal information of more than 100 million people, and hijacked computer servers to mine cryptocurrency," thundered US Attorney Nick Brown. "Far from being an ethical hacker trying to help companies with their computer security, she exploited mistakes to steal valuable data and sought to enrich herself."
"She wanted data, she wanted money, and she wanted to brag," Assistant United States Attorney Andrew Friedman said in closing arguments.
The Register contacted Thompson's lawyers for comment and will update should they respond. ®
Updated to add at 1446 UTC:
Capital One has been in touch to comment: "We are pleased with the outcome of the trial and remain thankful for the tireless work of the US Attorney's Office in Seattle and the FBI's Seattle Field Office in prosecuting this important case."
Get our [14]Tech Resources
[1] https://www.justice.gov/usao-wdwa/pr/former-seattle-tech-worker-convicted-wire-fraud-and-computer-intrusions
[2] https://www.theregister.com/2019/07/30/capital_one_hacked/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrCZp6OIIQj7@4thWXB1NQAAAFg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://regmedia.co.uk/2022/06/20/capital_one_complaint.pdf
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrCZp6OIIQj7@4thWXB1NQAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrCZp6OIIQj7@4thWXB1NQAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrCZp6OIIQj7@4thWXB1NQAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2019/08/06/wyden_amazon_letter/
[9] https://www.theregister.com/2019/08/05/github_and_capital_one_hit_by_class_action_suit/
[10] https://www.theregister.com/2019/07/30/capitalone_hacker_arrest/
[11] https://www.theregister.com/2019/07/30/capital_one_hacked/
[12] https://www.theregister.com/2020/08/07/capital_one_fine/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrCZp6OIIQj7@4thWXB1NQAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
Re: "Quite an expensive misconfiguration"
" It's not rocket science "
Nor is a pre-live pen test. But many of my clients have considered that to be an unnecessary expense.
"She wanted data, she wanted money, and she wanted to brag"
One incompatible purpose there. Bragging invites discovery.
Throw away the key (no pun intended)
Anyone who's suggesting the companies should be liable might want to re-read this sentence:
"she planted cryptocurrency mining software on new servers with the income from the mining going to her online wallet."
That's where it goes from - you should be grateful that somebody has found this security hole (and yes, at that point the company should be 100% liable) - to zero tolerance or respect for the person who "found" said hole.
There's a clear difference between people who find security breaches, report them and move on... to this.
They should lock the bastard up and ensure she's never allowed to use a computer again. Send a clear message.
Re: Throw away the key (no pun intended)
Over the top, your response?
-> They should lock the bastard up and ensure she's never allowed to use a computer again. Send a clear message.
The same doesn't happen to murderers, rapists, etc. But because this person started "mining" some crypto currency you get all Puritan? 'Tis the work of Beelzebub, I tell you.
Misconfigured or..
Misconfigured or configured for public access. How can one tell the difference?
Just an FYI
The perpetrator is a trans person who identifies as woman but is a male. I only bring it up because it is very notable to have a high profile female hacker, but this fact was excluded from the article.
Keeping data indefinitely?
-> credit card hopefuls between 2005 and early 2019
How about Capital One purge data after 10 years? I have no idea if records must be kept this long, but it seems that keeping an application after 17 years seems a bit over the top.
"Quite an expensive misconfiguration"
Indeed.
And I fail to see how a "financial giant" doesn't have personnel sufficiently trained to set up a server.
Ten years ago I set up a website for the company I was an associate in. It took me all of an hour to find the data to understand and properly lock down the .htaccess file to ensure that the entire file structure of our server would not be accessible.
I'm not an engineer, just a University-level graduate. It's not rocket science.