{"componentChunkName":"component---src-templates-post-js","path":"/resources/blog/capital-one-breach-security-tech-only-as-effective-as-the-human-configuring-it/","result":{"data":{"wordpress":{"post":{"id":"cG9zdDo1MzM3","title":"Capital One breach: security tech only as effective as the human configuring it","slug":"capital-one-breach-security-tech-only-as-effective-as-the-human-configuring-it","date":"2019-07-30T16:36:42","modifiedGmt":"2021-01-13T14:22:34","content":"\n<p>Capital One<a href=\"https://www.capitalone.com/facts2019/\" target=\"_blank\" rel=\"noreferrer noopener\"> this week announced</a> that a hacker stole personal information from over 100 million customers across North America. This included names, addresses, phone numbers, email addresses, dates of birth, self-reported income, and even social security numbers. The breach affected customers who submitted credit card applications between 2005 and 2019 – a whopping 14-year window.</p>\n\n\n\n<p>After discovering the breach on July 19, the bank immediately phoned its findings into federal law enforcement. Three days later, the FBI arrested Seattle software engineer Paige A. Thompson, aka ‘erratic’, who has since been charged with violating the US Computer Fraud and Abuse Act. Prosecutors claim that posts in a <a href=\"https://twitter.com/iangcarroll/status/1155986280234119170?s=20\" target=\"_blank\" rel=\"noreferrer noopener\">Slack channel from an individual calling themselves ‘erratic’</a> refer specifically to the hack.&nbsp;</p>\n\n\n\n<p>The<a href=\"https://www.justice.gov/usao-wdwa/press-release/file/1188626/download\" target=\"_blank\" rel=\"noreferrer noopener\"> FBI’s paperwork</a>&nbsp;alleges that Thompson broke into Capital One’s cloud-hosted storage, believed to be Amazon Web Services&#8217; S3 buckets, and downloaded its contents. Thompson worked for Amazon Web Services specializing in cloud storage systems between 2015 and 2016, so in this case, it seems it really did take one to know one.</p>\n\n\n\n<p>Capital One’s stance since the news broke is especially interesting. US prosecutors said Thompson was able to access the data because of a ‘misconfigured web application firewall’, whereas the bank spun things a little differently, blaming an ‘exploited configuration vulnerability’. Capital One is responsible and, like Equifax which was fined $575 million for its own<a href=\"https://www.ftc.gov/news-events/press-releases/2019/07/equifax-pay-575-million-part-settlement-ftc-cfpb-states-related\" target=\"_blank\" rel=\"noreferrer noopener\"> recent shortcomings</a>, will almost certainly be punished.</p>\n\n\n\n<p>The bottom line is that Capital One is trying to spin an error in its security tech configuration as an elite attacker breaking in. But the prosecutor and the FBI don&#8217;t pull punches. This one is the company’s mistake, and a mistake that must be owned.</p>\n\n\n\n<p>Most irksome for Capital One is how easily this sorry incident could&#8217;ve been avoided. The bank no doubt invests hundreds of thousands in its technology, but to what end if its people can’t actually use it? The effectiveness of security tech always comes back to the ability of defenders to understand the nature of the threat. If they don’t have the right skills at the right time, an attacker will make short work of bypassing their security.</p>\n\n\n\n<p>To prevent mistakes like this, companies should identify ways to show security teams what insecure systems look like. This will help defenders properly implement the expensive security tech at their disposal. Ultimately, it’s about putting people first, and remembering the importance of upskilling ourselves. ‘Humans are underrated,’ after all, to<a href=\"https://twitter.com/elonmusk/status/984882630947753984?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E984882630947753984&amp;ref_url=https%3A%2F%2Ftechcrunch.com%2F2018%2F04%2F13%2Felon-musk-says-humans-are-underrated-calls-teslas-excessive-automation-a-mistake%2F\" target=\"_blank\" rel=\"noreferrer noopener\"> quote</a> Elon Musk.</p>\n\n\n\n<p>The Immersive Labs platform is the best way to provide your security team with real cyber skills when they need them most. We keep our finger on the pulse using world-class threat intelligence, which means when a vulnerability comes to light, we aim to respond with interactive skills content the very same day. When it comes to understanding threats, theory learning is no match for handling real technology.</p>\n\n\n\n<p>Our Amazon S3 lab covers potential weaknesses in buckets as well as attacker methodology, and it could help protect your organization from a similar attack.</p>\n\n\n\n<p><strong>If you want to learn more about how Immersive Labs can upskill your security team within hours, get a demo today.</strong></p>\n\n\n","excerpt":"<p>Capital One this week announced that a hacker stole personal information from over 100 million customers across North America. This included names, addresses, phone numbers, email addresses, dates of birth, self-reported income, and even social security numbers. The breach affected customers who submitted credit card applications between 2005 and 2019 – a whopping 14-year window&#8230;.</p>\n","blocks":[{"__typename":"WordPress_CoreParagraphBlock","name":"core/paragraph","attributes":{"__typename":"WordPress_CoreParagraphBlockAttributes","content":"Capital One<a href=\"https://www.capitalone.com/facts2019/\" target=\"_blank\" rel=\"noreferrer noopener\"> this week announced</a> that a hacker stole personal information from over 100 million customers across North America. This included names, addresses, phone numbers, email addresses, dates of birth, self-reported income, and even social security numbers. The breach affected customers who submitted credit card applications between 2005 and 2019 – a whopping 14-year window.","textAlign":null,"fontSize":null}},{"__typename":"WordPress_CoreParagraphBlock","name":"core/paragraph","attributes":{"__typename":"WordPress_CoreParagraphBlockAttributes","content":"After discovering the breach on July 19, the bank immediately phoned its findings into federal law enforcement. Three days later, the FBI arrested Seattle software engineer Paige A. Thompson, aka ‘erratic’, who has since been charged with violating the US Computer Fraud and Abuse Act. Prosecutors claim that posts in a <a href=\"https://twitter.com/iangcarroll/status/1155986280234119170?s=20\" target=\"_blank\" rel=\"noreferrer noopener\">Slack channel from an individual calling themselves ‘erratic’</a> refer specifically to the hack.&nbsp;","textAlign":null,"fontSize":null}},{"__typename":"WordPress_CoreParagraphBlock","name":"core/paragraph","attributes":{"__typename":"WordPress_CoreParagraphBlockAttributes","content":"The<a href=\"https://www.justice.gov/usao-wdwa/press-release/file/1188626/download\" target=\"_blank\" rel=\"noreferrer noopener\"> FBI’s paperwork</a>&nbsp;alleges that Thompson broke into Capital One’s cloud-hosted storage, believed to be Amazon Web Services' S3 buckets, and downloaded its contents. Thompson worked for Amazon Web Services specializing in cloud storage systems between 2015 and 2016, so in this case, it seems it really did take one to know one.","textAlign":null,"fontSize":null}},{"__typename":"WordPress_CoreParagraphBlock","name":"core/paragraph","attributes":{"__typename":"WordPress_CoreParagraphBlockAttributes","content":"Capital One’s stance since the news broke is especially interesting. US prosecutors said Thompson was able to access the data because of a ‘misconfigured web application firewall’, whereas the bank spun things a little differently, blaming an ‘exploited configuration vulnerability’. Capital One is responsible and, like Equifax which was fined $575 million for its own<a href=\"https://www.ftc.gov/news-events/press-releases/2019/07/equifax-pay-575-million-part-settlement-ftc-cfpb-states-related\" target=\"_blank\" rel=\"noreferrer noopener\"> recent shortcomings</a>, will almost certainly be punished.","textAlign":null,"fontSize":null}},{"__typename":"WordPress_CoreParagraphBlock","name":"core/paragraph","attributes":{"__typename":"WordPress_CoreParagraphBlockAttributes","content":"The bottom line is that Capital One is trying to spin an error in its security tech configuration as an elite attacker breaking in. But the prosecutor and the FBI don't pull punches. This one is the company’s mistake, and a mistake that must be owned.","textAlign":null,"fontSize":null}},{"__typename":"WordPress_CoreParagraphBlock","name":"core/paragraph","attributes":{"__typename":"WordPress_CoreParagraphBlockAttributes","content":"Most irksome for Capital One is how easily this sorry incident could've been avoided. The bank no doubt invests hundreds of thousands in its technology, but to what end if its people can’t actually use it? The effectiveness of security tech always comes back to the ability of defenders to understand the nature of the threat. If they don’t have the right skills at the right time, an attacker will make short work of bypassing their security.","textAlign":null,"fontSize":null}},{"__typename":"WordPress_CoreParagraphBlock","name":"core/paragraph","attributes":{"__typename":"WordPress_CoreParagraphBlockAttributes","content":"To prevent mistakes like this, companies should identify ways to show security teams what insecure systems look like. This will help defenders properly implement the expensive security tech at their disposal. Ultimately, it’s about putting people first, and remembering the importance of upskilling ourselves. ‘Humans are underrated,’ after all, to<a href=\"https://twitter.com/elonmusk/status/984882630947753984?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E984882630947753984&amp;ref_url=https%3A%2F%2Ftechcrunch.com%2F2018%2F04%2F13%2Felon-musk-says-humans-are-underrated-calls-teslas-excessive-automation-a-mistake%2F\" target=\"_blank\" rel=\"noreferrer noopener\"> quote</a> Elon Musk.","textAlign":null,"fontSize":null}},{"__typename":"WordPress_CoreParagraphBlock","name":"core/paragraph","attributes":{"__typename":"WordPress_CoreParagraphBlockAttributes","content":"The Immersive Labs platform is the best way to provide your security team with real cyber skills when they need them most. We keep our finger on the pulse using world-class threat intelligence, which means when a vulnerability comes to light, we aim to respond with interactive skills content the very same day. When it comes to understanding threats, theory learning is no match for handling real technology.","textAlign":null,"fontSize":null}},{"__typename":"WordPress_CoreParagraphBlock","name":"core/paragraph","attributes":{"__typename":"WordPress_CoreParagraphBlockAttributes","content":"Our Amazon S3 lab covers potential weaknesses in buckets as well as attacker methodology, and it could help protect your organization from a similar attack.","textAlign":null,"fontSize":null}},{"__typename":"WordPress_CoreParagraphBlock","name":"core/paragraph","attributes":{"__typename":"WordPress_CoreParagraphBlockAttributes","content":"<strong>If you want to learn more about how Immersive Labs can upskill your security team within hours, get a demo today.</strong>","textAlign":null,"fontSize":null}},{"__typename":"WordPress_AcfCtaBlock","name":"acf/cta","acf":{"ctaNegativeBottomMargin":true,"ctaPost":{"__typename":"WordPress_Cta","id":"cG9zdDo3OTE3","attributes":{"ctaColor":"orangeMain","ctaTitle":"Ready to see for yourself?","ctaText":"Take a tour of our platform including the chance to get hands-on with emerging threats, CTF style challenges and playable cyber crisis simulations. ","ctaImage":{"sourceUrl":"https://cms.immersivelabs.com/content/uploads/2020/06/cta-demo-1-1300x288.png","imageFile":{"publicURL":"/static/d52c66fd6a9bf82b6641c6bac7b8ef11/cta-demo-1-1300x288.png","childImageSharp":{"fluid":{"base64":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAECAYAAACOXx+WAAAACXBIWXMAAAsTAAALEwEAmpwYAAAA4ElEQVQY062Pz0vCAACF92d614MHrx0DwRQxpFMMPAWlFkJBkWzNuVWi07lNXb+Yh67+WI6cJF7ec4e62NUHHx+8w4MncD/BnwU/WKI/8uC6Y7xHeEMPny9jyLdPSB+IyKQKyCXzyCeyKMYjYodoXNTRcT2Y/VcYzzZM3YKjmlyvfqLBRUBJ6/G4eM7SaY3iSYVOZ0D5SqZ4VKV0o7F5rbFx+UC1LFM9u6ehtNmy32g7H+y2BrQebYx0i4G/gLDZrDGZ+LiT2lB0E4pqYDr/wmw+xe+Vf3yHy8jY7RmuQmwBMJMbQYYHsSYAAAAASUVORK5CYII=","aspectRatio":4.545454545454546,"src":"/static/d52c66fd6a9bf82b6641c6bac7b8ef11/12f10/cta-demo-1-1300x288.png","srcSet":"/static/d52c66fd6a9bf82b6641c6bac7b8ef11/16ac3/cta-demo-1-1300x288.png 300w,\n/static/d52c66fd6a9bf82b6641c6bac7b8ef11/0e1f9/cta-demo-1-1300x288.png 600w,\n/static/d52c66fd6a9bf82b6641c6bac7b8ef11/12f10/cta-demo-1-1300x288.png 1200w,\n/static/d52c66fd6a9bf82b6641c6bac7b8ef11/808ee/cta-demo-1-1300x288.png 1300w","srcWebp":"/static/d52c66fd6a9bf82b6641c6bac7b8ef11/8edc8/cta-demo-1-1300x288.webp","srcSetWebp":"/static/d52c66fd6a9bf82b6641c6bac7b8ef11/fdc3b/cta-demo-1-1300x288.webp 300w,\n/static/d52c66fd6a9bf82b6641c6bac7b8ef11/47049/cta-demo-1-1300x288.webp 600w,\n/static/d52c66fd6a9bf82b6641c6bac7b8ef11/8edc8/cta-demo-1-1300x288.webp 1200w,\n/static/d52c66fd6a9bf82b6641c6bac7b8ef11/38bb9/cta-demo-1-1300x288.webp 1300w","sizes":"(max-width: 1200px) 100vw, 1200px"}}}},"ctaTitleSticky":null,"ctaTextSticky":null,"ctaButtonType":"link","ctaLink":{"target":"","title":"Get a demo","url":"https://www.immersivelabs.com/talk-to-an-expert"},"ctaButtonText":"Get a demo","ctaFormIntroContent":"<h3>Get a demo of Immersive Labs</h3>\n<p>Take just 30 minutes <span style=\"font-weight: 400;\">to embark on your journey to human cyber readiness. </span></p>\n","ctaHubspotPortalId":"3792509","ctaHubspotFormId":"7a5cd709-0200-4283-bb38-d32420a4efb7","ctaHubspotScript":"<!--[if lte IE 8]>\r\n<script charset=\"utf-8\" type=\"text/javascript\" src=\"//js.hsforms.net/forms/v2-legacy.js\"></script>\r\n<![endif]-->\r\n<script charset=\"utf-8\" type=\"text/javascript\" src=\"//js.hsforms.net/forms/v2.js\"></script>\r\n<script>\r\n  hbspt.forms.create({\r\n\tportalId: \"3792509\",\r\n\tformId: \"c008c5d5-2905-43ec-b9d0-2cfb1ee40a1d\",\r\n\tsfdcCampaignId: \"7014J000000dKYlQAM\",\r\n\tgoToWebinarWebinarKey: '3209713448464516878'\r\n});\r\n</script>"}}}}],"seo":{"title":"Security Tech Configuration & The Capital One Breach - Immersive Labs","metaDesc":"Capital One is trying to spin an error in its security tech configuration as an elite attacker breaking in. Learn more in our Immersive Labs blog post.","metaKeywords":"","canonical":"","opengraphType":"article","opengraphTitle":"Security Tech Configuration & The Capital One Breach - Immersive Labs","opengraphDescription":"Capital One is trying to spin an error in its security tech configuration as an elite attacker breaking in. Learn more in our Immersive Labs blog post.","opengraphImage":{"sourceUrl":"https://cms.immersivelabs.com/content/uploads/2019/07/shutterstock570926716.jpg","uri":"https://www.immersivelabs.com/resources/blog/capital-one-breach-security-tech-only-as-effective-as-the-human-configuring-it/shutterstock_570926716/"}},"featuredImage":{"sourceUrl":"https://cms.immersivelabs.com/content/uploads/2019/07/shutterstock570926716.jpg","imageFile":{"publicURL":"/static/70cb9ac4ae6afaad4379f8065b978ff8/shutterstock570926716.jpg","childImageSharp":{"fluid":{"base64":"data:image/jpeg;base64,/9j/2wBDABALDA4MChAODQ4SERATGCgaGBYWGDEjJR0oOjM9PDkzODdASFxOQERXRTc4UG1RV19iZ2hnPk1xeXBkeFxlZ2P/2wBDARESEhgVGC8aGi9jQjhCY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2P/wgARCAANABQDASIAAhEBAxEB/8QAFwAAAwEAAAAAAAAAAAAAAAAAAAQFA//EABYBAQEBAAAAAAAAAAAAAAAAAAIAA//aAAwDAQACEAMQAAABb0VWzdMmiv/EABoQAQACAwEAAAAAAAAAAAAAAAIDEQABIhL/2gAIAQEAAQUCgXClNUVka6mPjemq/8QAFhEBAQEAAAAAAAAAAAAAAAAAAQAR/9oACAEDAQE/ARtL/8QAFhEAAwAAAAAAAAAAAAAAAAAAAQIQ/9oACAECAQE/ASs//8QAGxAAAgIDAQAAAAAAAAAAAAAAADEBAhESUXH/2gAIAQEABj8C8YzMWKz1m9ZcjP/EABsQAQACAwEBAAAAAAAAAAAAAAEAESFRcWGh/9oACAEBAAE/IUc0GG0bqUrNcjHB9RSSKkPh8T//2gAMAwEAAgADAAAAEEwf/8QAFxEBAQEBAAAAAAAAAAAAAAAAAQAxUf/aAAgBAwEBPxATZTt//8QAFxEAAwEAAAAAAAAAAAAAAAAAAAERIf/aAAgBAgEBPxDSojP/xAAcEAEBAAMAAwEAAAAAAAAAAAABEQAhQVFhodH/2gAIAQEAAT8QIILNd07gg2Jaim5gc+vFZ0AUuIZflxgFMmoT9wERPQz/2Q==","aspectRatio":1.5,"src":"/static/70cb9ac4ae6afaad4379f8065b978ff8/1276b/shutterstock570926716.jpg","srcSet":"/static/70cb9ac4ae6afaad4379f8065b978ff8/6aaa1/shutterstock570926716.jpg 300w,\n/static/70cb9ac4ae6afaad4379f8065b978ff8/05631/shutterstock570926716.jpg 600w,\n/static/70cb9ac4ae6afaad4379f8065b978ff8/1276b/shutterstock570926716.jpg 1000w","srcWebp":"/static/70cb9ac4ae6afaad4379f8065b978ff8/a1ba4/shutterstock570926716.webp","srcSetWebp":"/static/70cb9ac4ae6afaad4379f8065b978ff8/fdc3b/shutterstock570926716.webp 300w,\n/static/70cb9ac4ae6afaad4379f8065b978ff8/47049/shutterstock570926716.webp 600w,\n/static/70cb9ac4ae6afaad4379f8065b978ff8/a1ba4/shutterstock570926716.webp 1000w","sizes":"(max-width: 1000px) 100vw, 1000px"}}}},"tags":{"edges":[{"node":{"name":"Blog","slug":"blog","count":114,"attributes":{"colorTheme":"electricBlue"}}},{"node":{"name":"In the News","slug":"in-the-news","count":99,"attributes":{"colorTheme":"violetMain"}}},{"node":{"name":"Threats","slug":"threats","count":21,"attributes":{"colorTheme":"electricBlue"}}}]},"categories":{"edges":[{"node":{"name":"All Resources","slug":"all-resources","count":352,"attributes":{"colorTheme":"electricBlue"}}},{"node":{"name":"Blog","slug":"blog","count":189,"attributes":{"colorTheme":"electricBlue"}}}]},"attributes":{"schema":"{\r\n  \"@context\": \"https://schema.org\",\r\n  \"@type\": \"NewsArticle\",\r\n  \"mainEntityOfPage\": {\r\n    \"@type\": \"WebPage\",\r\n    \"@id\": \"https://google.com/article\"\r\n  },\r\n  \"headline\": \"$title\",\r\n  \"image\": [\r\n    \"$featuredImage\"\r\n   ],\r\n  \"datePublished\": \"$date\",\r\n  \"dateModified\": \"$modified\",\r\n  \"author\": {\r\n    \"@type\": \"Person\",\r\n    \"name\": \"$author\"\r\n  },\r\n   \"publisher\": {\r\n    \"@type\": \"Organization\",\r\n    \"name\": \"Immersive Labs\",\r\n    \"logo\": {\r\n      \"@type\": \"ImageObject\",\r\n      \"url\": \"$logo\"\r\n    }\r\n  }\r\n}","postIncognito":null},"author":{"name":"Immersive Labs","attributes":{"userAvatarImage":{"altText":"","sourceUrl":"https://cms.immersivelabs.com/content/uploads/2020/06/0bdac40f82cf9e85a5e1cc04ef4a9af2.jpg","imageFile":{"publicURL":"/static/4b4dc210573184658e94223497b65cd5/0bdac40f82cf9e85a5e1cc04ef4a9af2.jpg","childImageSharp":{"fluid":{"base64":"data:image/jpeg;base64,/9j/2wBDABALDA4MChAODQ4SERATGCgaGBYWGDEjJR0oOjM9PDkzODdASFxOQERXRTc4UG1RV19iZ2hnPk1xeXBkeFxlZ2P/2wBDARESEhgVGC8aGi9jQjhCY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2NjY2P/wgARCAAUABQDASIAAhEBAxEB/8QAFwABAQEBAAAAAAAAAAAAAAAAAAUEA//EABQBAQAAAAAAAAAAAAAAAAAAAAD/2gAMAwEAAhADEAAAAaWTdOKwOU4KgP/EAB0QAAICAQUAAAAAAAAAAAAAAAEDAAIEERIiIzH/2gAIAQEAAQUCeSFrO1sYNaJt2S3mKOU//8QAFBEBAAAAAAAAAAAAAAAAAAAAIP/aAAgBAwEBPwEf/8QAFBEBAAAAAAAAAAAAAAAAAAAAIP/aAAgBAgEBPwEf/8QAGxABAAICAwAAAAAAAAAAAAAAAQIQABEhMWH/2gAIAQEABj8C4de4BKUh73Thtta//8QAHBAAAgICAwAAAAAAAAAAAAAAAREAMRAhQVHR/9oACAEBAAE/IeRE76CNLBYFwXYgEO9wW0ALRFRz/9oADAMBAAIAAwAAABCzDwD/xAAUEQEAAAAAAAAAAAAAAAAAAAAg/9oACAEDAQE/EB//xAAUEQEAAAAAAAAAAAAAAAAAAAAg/9oACAECAQE/EB//xAAcEAEAAgIDAQAAAAAAAAAAAAABABEhQRAxUWH/2gAIAQEAAT8QcK0AC3ZUfyQBMXjhHFEs8SOcEsL0uFS6sTEcGDSdZl/k/9k=","aspectRatio":1,"src":"/static/4b4dc210573184658e94223497b65cd5/5c772/0bdac40f82cf9e85a5e1cc04ef4a9af2.jpg","srcSet":"/static/4b4dc210573184658e94223497b65cd5/07fa7/0bdac40f82cf9e85a5e1cc04ef4a9af2.jpg 150w,\n/static/4b4dc210573184658e94223497b65cd5/5c772/0bdac40f82cf9e85a5e1cc04ef4a9af2.jpg 192w","srcWebp":"/static/4b4dc210573184658e94223497b65cd5/0814e/0bdac40f82cf9e85a5e1cc04ef4a9af2.webp","srcSetWebp":"/static/4b4dc210573184658e94223497b65cd5/ef536/0bdac40f82cf9e85a5e1cc04ef4a9af2.webp 150w,\n/static/4b4dc210573184658e94223497b65cd5/0814e/0bdac40f82cf9e85a5e1cc04ef4a9af2.webp 192w","sizes":"(max-width: 192px) 100vw, 192px"}}}},"userJobTitle":"Senior Developer"}}}}},"pageContext":{"id":"cG9zdDo1MzM3","slug":"capital-one-breach-security-tech-only-as-effective-as-the-human-configuring-it"}},"staticQueryHashes":["1134781590","1430943121","1691173908","2407081983","2499683418","3123027226","3518138710","3678308812","4001368598","4116960265","437961647"]}