. Military Space News .
CYBER WARS
US woman charged in massive Capital One data breach
By Jocelyne ZABLIT
Los Angeles (AFP) July 30, 2019

A tech engineer in the western US state of Washington was arrested Monday on charges of stealing sensitive data from more than 100 million credit card applications at financial heavyweight Capital One.

Paige Thompson, 33, a former Seattle technology company software engineer, was nabbed by FBI agents after she boasted about the data theft -- one of the biggest to hit a financial services company -- on the information sharing site GitHub, authorities said.

"The intrusion occurred through a misconfigured web application firewall that enabled access to the data," a statement by the US attorney's office in Washington said.

"On July 17, 2019, a GitHub user who saw the post alerted Capital One to the possibility it had suffered a data theft."

It said the Virginia-based bank that specializes in credit cards contacted the FBI after confirming the data theft, which took place between March 12 and July 17 of this year.

"According to Capital One, the data includes data regarding large numbers of (credit card) applications, likely tens of millions of applications," according to the criminal complaint.

In a statement, Capital One said the hack affected 100 million individuals in the United States and six million in Canada.

"Importantly, no credit card account numbers or log-in credentials were compromised and over 99 percent of social security numbers were not compromised," the bank said.

- 'Sincerely apologize'

Thompson, who used the alias "erratic" in online conversations, allegedly posted several times about the theft on GitHub and on social media.

One posting on a Twitter account with the user name "erratic" read: "I've basically strapped myself with a bomb vest, fucking dropping capital ones dox and admitting it," according to the complaint.

Authorities said electronic storage devices containing a copy of the stolen data were recovered at her residence on Monday.

Capital One said some of the information in the applications stolen, such as social security numbers, is encrypted or tokenized. Other information including names, addresses, dates of birth and credit card history was not secured.

The company said it expects the breach to cost between $100 to $150 million in 2019. It added that free credit monitoring and identity protection would be made available to anyone affected.

"While I am grateful that the perpetrator has been caught, I am deeply sorry for what has happened," Richard Fairbank, the company's chairman and CEO, said in a statement. "I sincerely apologize for the understandable worry this incident must be causing those affected and I am committed to making it right."

Thompson faces up to five years in prison and a $250,000 fine if convicted of on the charge of computer fraud.

   She was ordered held in jail Monday pending a detention   hearing later 
this week.

News of the Capital One breach comes after US credit monitoring agency Equifax last week agreed to pay up to $700 million to settle a similar incident that hit the company in 2017, affecting nearly 150 million customers.

The penalty was the biggest ever in a data breach case and followed revelations that hackers had stolen the personal details of millions, including names, dates of birth and social security numbers.

jz/it

CAPITAL ONE FINANCIAL

EQUIFAX


Related Links
Cyberwar - Internet Security News - Systems and Policy Issues


Thanks for being here;
We need your help. The SpaceDaily news network continues to grow but revenues have never been harder to maintain.

With the rise of Ad Blockers, and Facebook - our traditional revenue sources via quality network advertising continues to decline. And unlike so many other news sites, we don't have a paywall - with those annoying usernames and passwords.

Our news coverage takes time and effort to publish 365 days a year.

If you find our news sites informative and useful then please consider becoming a regular supporter or for now make a one off contribution.
SpaceDaily Contributor
$5 Billed Once


credit card or paypal
SpaceDaily Monthly Supporter
$5 Billed Monthly


paypal only


CYBER WARS
Britain waits for US before Huawei 5G decision
London (AFP) July 22, 2019
Britain said Monday it was "not yet in a position" to decide what involvement China's Huawei should have in the UK's 5G next-generation telecoms network. Digital Secretary Jeremy Wright told parliament that London was still seeking clarity on the implications of US action against the Chinese telecoms giant, adding it would be "wrong to make specific decisions" beforehand. "The government is not yet in a position to decide what involvement Huawei should have in the provision of the UK's 5G networ ... read more

Comment using your Disqus, Facebook, Google or Twitter login.



Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle

CYBER WARS
Lockheed Martin gets $22.5M contract for Aegis upgrades

Lockheed awarded $1.4B contract for Saudi THAAD system

China tested new anti-ballistic missile in South China Sea

Trump declines to criticize Turkey's Russia missile purchase

CYBER WARS
Missiles 'probably' from Israel fired into south Syria: monitor

Paris says its missiles found on pro-Haftar rebel base in Libya

Lockheed awarded $492.1M to produce HIMARS for U.S., Poland, Romania

Missile seized in Italy sold to third country in 1994: Qatar

CYBER WARS
US may have downed two Iranian drones last week: general

U.S. Defense Department considers buying Israeli-made drones

C-Astral participates in demonstrations to help Europe set rules for drone deliveries

Navy's Fire Scout unmanned helicopter achieves initial operational capability

CYBER WARS
Newly established US Space Agency offers sneak peek at satellite layout

AEHF-5 encapsulated and prepared for launch

Corps begins fielding mobile satellite communication system

AFRL demonstrates world's first daytime free-space quantum communication enabled by adaptive optics

CYBER WARS
BAE Systems wins $45M contract for howitzer modifications

Leidos Inc. awarded $66.7M for Air Force Research Lab C4ISR sensor work

Oshkosh Defense awarded $320M to supply FMTVs for U.S., allies

Air Force rolls out new medical model to minimize troop downtime

CYBER WARS
Turkey convinced Trump wants to avoid sanctions over S-400

US finally gets new Pentagon chief as Senate confirms Esper

Trump doesn't see sanctions 'right now' on Turkey

US bars Turkey from F-35 program over Russian missiles

CYBER WARS
China eyes high-tech army, says US undermines global stability

Vietnam criticises China over vessels in disputed waters

Philippines refloats tourism plans for disputed South China Sea island

China defends air patrol with Russia after S. Korea, Japan fury

CYBER WARS
DARPA Announces Microsystems Exploration Program

Monitoring the lifecycle of tiny catalyst nanoparticles









The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.