U.S. v. Paige Thompson (Capital One AWS Cloud SSRF Breach)
Key Facts
- Legal Status: SENTENCED in U.S. District Court for the Western District of Pennsylvania and Western District of Washington.
- Primary Target Sector: Financial Services, Cloud Computing.
- Documented Financial Loss: $270.0 million.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity Web Application Firewall (WAF) hosted on an Amazon Web Services EC2 instance.
Operational & Financial Fallout
Over 100 million credit card applications, 140,000 Social Security numbers, and 80,000 linked bank account numbers exfiltrated from 700 Amazon S3 storage buckets. Capital One paid an $80 million regulatory fine and a $190 million class action settlement.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity Web Application Firewall (WAF) hosted on an Amazon Web Services EC2 instance.
Adversary Kill Chain Flow
3 Documented PhasesThompson sent crafted HTTP requests to the misconfigured WAF, tricking it into querying the AWS local metadata service (169.254.169.254) and returning temporary security credentials for an IAM role.
The stolen IAM role (*PRIV_WA_SCAN*) possessed excessive permissions allowing the attacker to list and read all files across Capital One's Amazon S3 object storage environment.
Using high-speed multithreaded cloud CLI scripts, Thompson downloaded over 700 buckets containing 100M+ customer applications to her personal server, then discussed the breach on Slack and posted scripts to GitHub.
Over 100 million credit card applications, 140,000 Social Security numbers, and 80,000 linked bank account numbers exfiltrated from 700 Amazon S3 storage buckets. Capital One paid an $80 million regulatory fine and a $190 million class action settlement.
Procedural & Incident Timeline
Federal grand jury indicts Thompson on wire fraud and seven counts of computer intrusion.
Jury finds Thompson guilty of wire fraud, unauthorized access to a protected computer, and damaging a protected computer.
Court sentences Thompson to time served and five years of supervised release.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Paige Adele Thompson | United States | convicted | Pending | None | Perpetrator of Capital One cloud data breach; convicted of wire fraud and computer intrusion. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Thompson executed Server-Side Request Forgery (SSRF) requests against a misconfigured ModSecurity WAF running on an EC2 instance, instructing the server to query the local AWS instance metadata service at 169.254.169.254." | Indictment ¶ 8, Page 3 | reviewed |
| T1078 | Valid Accounts Defense Evasion | "The metadata response yielded temporary security credentials for an IAM role named *PRIV_WA_SCAN*, which possessed excessive permissions to enumerate and download files from Capital One Amazon S3 buckets." | Trial Exhibit 14, Criminal Complaint ¶ 12 | reviewed |
| T1567 | Exfiltration Over Web Service Exfiltration | "Using multithreaded cloud CLI commands, the defendant downloaded over 700 S3 buckets containing approximately 100 million credit card applications, Social Security numbers, and bank account details." | Indictment ¶ 11, Page 5 | reviewed |