CASE DOSSIER sentenced

U.S. v. Paige Thompson (Capital One AWS Cloud SSRF Breach)

Docket: 2:19-cr-00159 Court: U.S. District Court for the Western District of Pennsylvania and Western District of Washington Opened: 2019-08-28 Sector: Financial Services, Cloud Computing

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$270.0 million
Capital One agreed to pay an $80 million regulatory fine to the OCC and a $190 million class-action consumer settlement.
Techniques
3
Verified mappings
Defendants
1
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Western District of Pennsylvania and Western District of Washington.
  • Primary Target Sector: Financial Services, Cloud Computing.
  • Documented Financial Loss: $270.0 million.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Former Amazon Web Services systems engineer convicted under the Computer Fraud and Abuse Act for exploiting a misconfigured open-source Web Application Firewall (WAF) using Server-Side Request Forgery (SSRF) to query AWS metadata services and steal over 100 million credit card applications from Capital One.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity Web Application Firewall (WAF) hosted on an Amazon Web Services EC2 instance.

Operational & Financial Fallout

Over 100 million credit card applications, 140,000 Social Security numbers, and 80,000 linked bank account numbers exfiltrated from 700 Amazon S3 storage buckets. Capital One paid an $80 million regulatory fine and a $190 million class action settlement.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity Web Application Firewall (WAF) hosted on an Amazon Web Services EC2 instance.

Adversary Kill Chain Flow

3 Documented Phases
1
SSRF Exploitation Metadata Service Credential Theft
MITRE ATT&CK T1190 →

Thompson sent crafted HTTP requests to the misconfigured WAF, tricking it into querying the AWS local metadata service (169.254.169.254) and returning temporary security credentials for an IAM role.

Artifacts & Tooling: SSRF vulnerability AWS EC2 Instance Metadata Service (IMDSv1)
2
Privilege Abuse Overprivileged IAM Role Enumeration
MITRE ATT&CK T1078 →

The stolen IAM role (*PRIV_WA_SCAN*) possessed excessive permissions allowing the attacker to list and read all files across Capital One's Amazon S3 object storage environment.

Artifacts & Tooling: AWS IAM role: PRIV_WA_SCAN aws s3 ls commands
3
Automated Cloud Exfiltration Mass S3 Bucket Download and Public Boasting
MITRE ATT&CK T1567 →

Using high-speed multithreaded cloud CLI scripts, Thompson downloaded over 700 buckets containing 100M+ customer applications to her personal server, then discussed the breach on Slack and posted scripts to GitHub.

Artifacts & Tooling: aws s3 sync scripts GitHub public repository commits
Real-World Blast Radius & Operational Fallout

Over 100 million credit card applications, 140,000 Social Security numbers, and 80,000 linked bank account numbers exfiltrated from 700 Amazon S3 storage buckets. Capital One paid an $80 million regulatory fine and a $190 million class action settlement.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce AWS Instance Metadata Service Version 2 (IMDSv2) across all EC2 instances to require session tokens and block SSRF attacks.
✓ Apply principle of least privilege to IAM roles, ensuring WAF instances cannot read customer databases or S3 storage.
✓ Deploy S3 Object Lock and real-time AWS CloudTrail alerts for anomalous bulk S3 GetObject API calls.
✓ Regularly audit cloud configurations against CIS AWS Foundations Benchmarks.

Procedural & Incident Timeline

2019-08-28 indictment

Federal grand jury indicts Thompson on wire fraud and seven counts of computer intrusion.

2022-06-17 verdict

Jury finds Thompson guilty of wire fraud, unauthorized access to a protected computer, and damaging a protected computer.

2022-10-04 sentencing

Court sentences Thompson to time served and five years of supervised release.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Paige Adele Thompson United States convicted Pending None Perpetrator of Capital One cloud data breach; convicted of wire fraud and computer intrusion.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"Thompson executed Server-Side Request Forgery (SSRF) requests against a misconfigured ModSecurity WAF running on an EC2 instance, instructing the server to query the local AWS instance metadata service at 169.254.169.254." Indictment ¶ 8, Page 3 reviewed
T1078 Valid Accounts
Defense Evasion
"The metadata response yielded temporary security credentials for an IAM role named *PRIV_WA_SCAN*, which possessed excessive permissions to enumerate and download files from Capital One Amazon S3 buckets." Trial Exhibit 14, Criminal Complaint ¶ 12 reviewed
T1567 Exfiltration Over Web Service
Exfiltration
"Using multithreaded cloud CLI commands, the defendant downloaded over 700 S3 buckets containing approximately 100 million credit card applications, Social Security numbers, and bank account details." Indictment ¶ 11, Page 5 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Paige Thompson (Capital One AWS Cloud SSRF Breach), No. 2:19-cr-00159 (U.S. District Court for the Western District of Pennsylvania and Western District of Washington 2019), https://cybercaselibrary.com/cases/us-v-thompson-capital-one/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-thompson-capital-one" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>