Capital One, 2019: a cloud configuration gap and an $80 million penalty.
An outside individual reached customer data stored in Capital One's cloud environment. The bank's regulator later found it had moved to the cloud without effective risk assessment. What the official record says, and the controls it points to.
Last updated Published by TryTrustableNot legal advice
In March 2019 an outside individual used what Capital One called a configuration vulnerability to obtain data on about 100 million people in the US and about 6 million in Canada. Capital One learned of it on 19 July 2019 after a tip through its responsible disclosure programme. In August 2020 the US Office of the Comptroller of the Currency fined the bank $80 million, finding it had not established effective risk assessment before migrating IT operations to the public cloud, with weaknesses in network security controls, data loss prevention and the handling of alerts.
What happened
| Date | What happened |
|---|---|
| 22 and 23 March 2019 | Unauthorised access to customer data occurs, according to Capital One. |
| 17 July 2019 | An external security researcher reports the configuration vulnerability through Capital One's Responsible Disclosure Program. |
| 19 July 2019 | Capital One determines that an outside individual gained unauthorised access. |
| After discovery | The individual who took the data is captured by the FBI. Capital One states the government believes the data was recovered, with no evidence it was used for fraud or shared. |
| 6 August 2020 | The OCC announces an $80 million civil money penalty and a consent order. |
Capital One's own incident page is the primary account of the dates and the data. It is short and specific: the access happened over two days in March, and the bank found out four months later because someone outside the company reported it (Capital One, 2019 cyber incident facts).
Root cause
Capital One describes the entry point as a configuration vulnerability in its cloud environment. The OCC's consent order goes further on the organisational causes. It finds that, in or around 2015, the bank "failed to establish effective risk assessment processes" before migrating IT operations to the cloud, and did not establish appropriate risk management for that environment, including the design and implementation of certain network security controls, adequate data loss prevention controls and effective dispositioning of alerts (OCC consent order AA-EC-20-51).
The order also finds that internal audit failed to identify numerous control weaknesses in the cloud environment and did not report them effectively to the Audit Committee, and that the Board did not hold management accountable for gaps raised by audit. Capital One neither admitted nor denied the findings.
Read together, the official record describes two layers: a technical misconfiguration that made the data reachable, and governance that did not catch the weakness before an outsider did. This page does not go beyond those findings: more detailed technical accounts exist in press coverage and court reporting, but they are not repeated here.
Impact and regulatory outcome
- People affected: about 100 million individuals in the United States and about 6 million in Canada, according to Capital One.
- Data: mostly data from credit card applications made from 2005 to early 2019, such as names, addresses, phone numbers, email addresses, dates of birth and self-reported income. Capital One reports about 140,000 US Social Security numbers, about 80,000 linked bank account numbers and about 1 million Canadian Social Insurance Numbers.
- Regulator: the OCC assessed an $80 million civil money penalty on 6 August 2020, for noncompliance with the Interagency Guidelines Establishing Information Security Standards (12 C.F.R. Part 30, Appendix B) and unsafe or unsound practices.
The OCC penalty is about governance as much as technology: the findings name risk assessment, internal audit and Board oversight alongside the network and data loss controls.
The controls that address it
| Control | SOC 2 criteria | ISO 27001:2022 Annex A |
|---|---|---|
| Risk assessment before significant change, including a move to the cloud | CC3.2, CC3.4 | A.5.23, A.8.32 |
| Secure configuration baselines for cloud resources, checked continuously | CC7.1, CC8.1 | A.8.9 |
| Least privilege for roles and service identities | CC6.1, CC6.3 | A.5.15, A.5.18, A.8.2 |
| Network security controls and segregation | CC6.6 | A.8.20, A.8.22 |
| Data loss prevention for sensitive stores | CC6.7 | A.8.12 |
| Logging, monitoring and timely triage of alerts | CC7.2, CC7.3 | A.8.15, A.8.16 |
| Independent review of control effectiveness reported to governance | CC4.1, CC4.2 | A.5.35 |
SOC 2 references are the 2017 Trust Services Criteria (points of focus revised 2022); Annex A references are ISO/IEC 27001:2022. These are the usual mappings: agree yours with your auditor.
How TryTrustable checks these controls
TryTrustable reads your cloud accounts with read-only credentials and re-runs these checks on a schedule, so a configuration that drifts shows up as a failed control rather than waiting for the next audit:
- AWS (integration): S3 Block Public Access at account level; a multi-region CloudTrail trail with log file validation; GuardDuty and Security Hub enabled in every region; no root access keys; access key age; RDS storage encryption and RDS instances not publicly accessible.
- GCP (integration): service accounts that hold Owner or Editor, user-managed service-account keys, Data Access audit logs, Cloud SQL not open to the internet, and whether Security Command Center is enabled.
- Infrastructure as code: the SDK in your CI analyses Terraform and Kubernetes configuration before it is applied, and the pre-push gate can block a change that fails.
- Web security testing:
trytrustable dastruns OWASP ZAP and Nuclei against your own applications (web security testing).
These are the checks TryTrustable runs today. None of them is a claim about what would have happened in this incident: they test whether the control is in place in your environment, continuously, and record the result as audit evidence.
Sources
- Capital One: Information on the 2019 cyber incident
- OCC news release 2020-101: OCC assesses $80 million civil money penalty against Capital One (6 August 2020)
- OCC consent order, In the Matter of Capital One, N.A. and Capital One Bank (USA), N.A., AA-EC-20-51
Every figure on this page is taken from the official documents listed here, read in October 2026. Regulatory findings quoted are the regulator's; where a company neither admitted nor denied them, or where proceedings are still open, the page says so. Not legal advice.
More case studies: all breach case studies · Research
The things people ask us
How many people did the Capital One breach affect?
About 100 million individuals in the United States and about 6 million in Canada, according to Capital One's incident page. Most of the data came from credit card applications; about 140,000 US Social Security numbers and about 80,000 linked bank account numbers were included.
What penalty did Capital One pay?
The US Office of the Comptroller of the Currency assessed an $80 million civil money penalty on 6 August 2020. It found the bank had not established effective risk assessment before migrating IT operations to the cloud, and had weaknesses in network security controls, data loss prevention and alert handling.
How was the Capital One breach discovered?
An external security researcher reported the configuration vulnerability through Capital One's responsible disclosure programme on 17 July 2019. Capital One confirmed the unauthorised access on 19 July 2019, about four months after it happened.
What is the main lesson for a SaaS company?
Cloud configuration and identity permissions need continuous checking, and someone has to own the alerts. The OCC also faulted internal audit and Board oversight, so evidence that controls are reviewed matters as much as the controls themselves.
Check these controls in your own environment.
We connect GitHub and one cloud account in a demo and show which of these checks pass, with the evidence an auditor would ask for.