So Capital One dropped the breach news today and I've been half-reading the filing on my phone between meetings, which is not how I intended to spend my Monday. Over 100 million people in the US, about 6 million more in Canada. Names, addresses, credit scores, self-reported income on applications going back to 2005. Something like 140,000 Social Security numbers and 80,000 linked bank account numbers got pulled too, which is the part that actually matters if you're one of the people in that pile.
Here's the thing that's sticking with me though, and it's not the number. It's how boring the actual break-in was.
The FBI arrested a woman named Paige Thompson in Seattle, and according to the complaint she used to work at Amazon Web Services. Not Capital One's AWS account, just AWS generally, as an engineer, a few years back. The exploit itself wasn't some exotic zero-day she'd been sitting on. It was a misconfigured web application firewall sitting in front of a Capital One server, hosted on AWS, that let her make a request that tricked the server into fetching credentials it shouldn't have handed over, and from there she could reach into the S3 storage buckets where all this data was sitting. That's it. That's the whole hack. A firewall rule that was set up wrong.
I keep thinking back to when I wrote about the Equifax mess on here two summers ago, and how that one traced back to an unpatched Apache Struts vulnerability that had a fix available for months before anyone at Equifax bothered applying it. Different company, different cloud setup, same basic story: not a supervillain, just somebody's checklist item that got skipped. We keep acting shocked that the biggest breaches come from boring causes instead of nation-state hacking teams, and I genuinely don't understand why we're still shocked. The boring cause is always going to be more common because there are a thousand boring misconfigurations for every one brilliant exploit chain, and most companies running anything at this scale have way more surface area than people watching it.
What bugs me is the framing every story I've read today keeps reaching for, this idea that cloud infrastructure is inherently less safe than running your own servers. That's not really what happened here. The vulnerability was in how Capital One set up their firewall and their permissions, not in AWS as a platform. If anything the forensics on this were only possible because everything left a trail in AWS logs, which is more than you'd get out of a lot of on-prem setups I've dealt with over the years. The problem isn't the cloud. The problem is that "moved to the cloud" doesn't mean "someone configured the cloud correctly," and those are two very different sentences that keep getting treated as the same one in press releases.
Capital One says they'll notify everyone affected and offer free credit monitoring, which, sure, fine, that's the script at this point. I've had four of these emails land in my inbox since 2017 and I've stopped opening the monitoring dashboards because at some point checking obsessively just makes you anxious without actually protecting anything. My data's already out there in some combination from Equifax, from whatever the Marriott thing was last year, probably from two or three others I've forgotten about. A credit freeze is still the only thing I've done that felt like it actually changed anything, and I did that back in 2017 and never bothered undoing it.
The stock dropped a few points after hours, which it'll probably recover from within a month or two, because that's what always happens. The actual fallout, if there is any, will be lawsuits and a Senate hearing sometime this fall where a Capital One executive says the word "unacceptable" a lot and not much changes structurally afterward. I'd love to be wrong about that part.
If you've got a Capital One card, go check your account activity tonight instead of scrolling Twitter. It'll take five minutes and it's a better use of the five minutes.