U.S. v. Paige Thompson (Capital One Cloud Breach)
Key Facts
- Legal Status: CONVICTED in U.S. District Court for the Western District of Washington.
- Primary Target Sector: Financial Services, Cloud Computing.
- Documented Financial Loss: $270.0 million.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Adversary breached the target network via Exploit Public-Facing Application. Thompson sent crafted HTTP requests exploiting a Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity WAF.
Operational & Financial Fallout
Capital One incurred $270 million in customer notifications, legal settlements, and regulatory fines. Impacted Financial Services, Cloud Computing infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Adversary breached the target network via Exploit Public-Facing Application. Thompson sent crafted HTTP requests exploiting a Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity WAF.
Adversary Kill Chain Flow
3 Documented PhasesThompson sent crafted HTTP requests exploiting a Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity WAF.
Obtained temporary security credentials from the AWS EC2 instance metadata service to access private S3 storage buckets.
Thompson ran automated aws-s3 listing commands to enumerate bucket contents across victim customer directories.
Capital One incurred $270 million in customer notifications, legal settlements, and regulatory fines. Impacted Financial Services, Cloud Computing infrastructure and associated victim operations.
Procedural & Incident Timeline
FBI agents arrest Thompson at her residence in Seattle.
Jury finds Thompson guilty of wire fraud and six counts of unauthorized access to a protected computer.
Sentenced to time served and five years of supervised release with restitution ordered.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Paige Adele Thompson | United States | convicted | Pending | None | Perpetrator of Capital One cloud data breach; convicted of wire fraud and computer intrusion. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Thompson sent crafted HTTP requests exploiting a Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity WAF." | Indictment ¶ 9, Page 4 | reviewed |
| T1078 | Valid Accounts Defense Evasion | "Obtained temporary security credentials from the AWS EC2 instance metadata service to access private S3 storage buckets." | Trial Transcript Day 3, Page 54 | reviewed |
| T1083 | File and Directory Discovery Discovery | "Thompson ran automated aws-s3 listing commands to enumerate bucket contents across victim customer directories." | Indictment ¶ 12, Page 6 | reviewed |