Jump to content

BREAKING: Capital One is facing a federal class action over a massive data breach


tacobell fan

Recommended Posts

1 minute ago, Chinna84 said:

Amazon stock 10gutundhaa ippudu ??

no, its misconfig from CapitalOne...not Amazons fault.

  • Thanks 1
Link to comment
Share on other sites

  • Replies 37
  • Created
  • Last Reply

Top Posters In This Topic

  • Spartan

    8

  • shaw183

    6

  • tacobell fan

    5

  • dasara_bullodu

    3

Popular Days

2 minutes ago, CNR said:

I understood the part using waf role got access to s3 bucket . In order to execute the command she should execute from server or aws cli. Assuming server ki acess vachi execute cheste , then that is capital one bank negligence about firewall mosconfiguration. Vulnerability or misoc figuration ani doubt ?? Capital one bank motam programmers hava

That’s the dumbest thing. Allowing Developers to access the Infrastructure specially how the storage is handled. Probably it’s a good reason why traditionally companies hired Admins/System Admins and train them versus A developer. Admins not necessarily know the dev/coding and it’s hard for them to open a code and make changes. But it’s not the same with other way. When you allow storage permissions which AWS is doing with ease of access to anyone can handle storage needs these issues will become more apparent. Other major banks did not allow AWS or Public Storage servers just for these reasons. 

Link to comment
Share on other sites

8 minutes ago, Spartan said:

no, its misconfig from CapitalOne...not Amazons fault.

TRue..amzn lolli em ledu endulo...i wonder why they started cooking that news lol 

Linux vadinanduku IBM vadidi tapu anela unaru media

Link to comment
Share on other sites

2 hours ago, tacobell fan said:

Capital One is facing a federal class action filed hours after it disclosed a massive data breach implicating the personal information of millions of customers.

The company announced July 29 that a hacker had gained access to the personal information of about 106 million credit card customers and applicants, including about 140,000 Social Security numbers, 1 million Canadian Social Insurance numbers, and 80,000 bank account numbers. 

“The largest category of information accessed was information on consumers and small businesses as of the time they applied for one of our credit card products from 2005 through early 2019,” the company said. This information also included names, addresses, phone numbers, email addresses, dates of birth, and self-reported income. The hacker also obtained portions of credit card customer data, including credit scores, credit limits, balances, and payment history, and fragments of transaction data, the company said.

The U.S. Justice Department has arrested a suspect, a former Seattle technology company software engineer. The intrusion occurred through a misconfigured web application firewall that enabled access to the data, according to the DOJ. 

The company promised to make free credit monitoring and identity protection available to those affected.

Kevin Zosiak filed suit in the U.S. District Court for the District of Columbia July 30, saying the breach has left Capital One’s customers like him vulnerable to identity theft. 

The company failed to maintain an adequate data security system to reduce the risk of data breaches and cyber-attacks, and failed to adequately monitoring its system to identify such threats, despite “ample warnings of weaknesses and risks to its systems” through past security breaches, Zosiak claims.

He has asked the court to certify the case as a class action.

New York announced July 30 that it is opening an investigation into the data breach. 

Cause of Action: Negligence, negligence per se, breach of implied contract.

Relief: Zosiak is seeking an unspecified level of damages on behalf of these customers and applicants.

Potential Class Size: More than 106 million members.

Response: Capital One didn’t immediately respond to Bloomberg Law’s request for comment.

Attorneys: Zosiak is represented by Nussbaum Law Group P.C.

The case is Zosiak v. Capital One Financial Corp., D.D.C., No. 1:19-cv-02265, filed 7/30/19.

 

oh.. sooper.. ayithey malli manakoka $125 osthaya?? @tacobell fan kaka

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...