Capital One Data Breach – 100 Million Affected [Update]

Update: Despite Capital One stating that the information was not disseminated the hacker posted it on their public github and at least one person accessed that data (as they reported the breach to Capital One). Wired has more in depth information on this.

Capital One has announced that data of approximately 100 million individuals in the United States (and approximately 6 million in Canada) has been accessed by an outside individual in the latest data breach. The FBI has arrested the individual responsible for the breach and Capital One believes that the information stolen has not been disseminated.

Contents

Key Facts

  • No credit card numbers or log in details were stolen
  • Over 99% of social security numbers were not compromised (140,000 social security numbers were stolen & 80,000 linked bank account numbers). The social security numbers that were stolen were from customers that used their Social Security number as their Employer Identification number in applying for small business credit cards
  • Stolen data includes names, addresses, zip codes/postal codes, phone numbers, email addresses, dates of birth, and self-reported income
  • Credit credit data was also stolen:
    • Customer status data, e.g., credit scores, credit limits, balances, payment history, contact information
    • Fragments of transaction data from a total of 23 days during 2016, 2017 and 2018

Final Thoughts

It’s unclear how Capital One will be helping affected customers at this stage. It’s good that the individual has been apprehended but I’m always cautious when corporations say that the data has not been disseminated as we do not know on what basis they are making that claim and often times that statement is revised down the line as new information comes to light.

I’ve said it before and I’ll say it again, until the penalties for data breaches are increased they will continue to occur at an alarming rate. The damage that can be done to individuals when this data is stolen can be significant and I don’t believe corporations are investing enough resources into informational security.

Subscribe
Notify of
guest

64 Comments
newest
oldest most voted

Charles Mann
Charles Mann (@guest_797277)
August 12, 2019 21:55

Got a letter from Cap One today re: data breach, they are offering two years of credit monitoring thru “myTrueidentity” (part of Transunion). Anyone know more about this or have any opinions regarding this?

Wayne kidd
Wayne kidd (@guest_791190)
July 30, 2019 11:58

Anything can happen and I mean anything at any given time regardless of efforts to stop it.REGARDLESS!!! It will happen anyway and is happening at this very moment.
There is no getting around it,”the love of money is A root of evil!!! So go for it……

anonymous
anonymous (@guest_791185)
July 30, 2019 11:48

I wonder if Capital One is now regretting having turned away so many potential paying customers. They could probably use that extra cash now.

max martori
max martori (@guest_791157)
July 30, 2019 11:05

I know someone who used a social security number as an EIN for a small business card (those were the only people affected) and someone tried to sign up for a cc in their name may be a coincidence but I doubt it. These big mean credit card companies should be heavily fined for such activity this is getting out of hand. Every other day you hear about another breach. Be on the lookout folks!

Nick
Nick (@guest_791071)
July 30, 2019 08:48

Whoever wrote the line “No bank account numbers or Social Security numbers were compromised” other than about 140,000 Social Security Numbers and 80,000 bank account numbers, should be fired. Talk about downplaying a serious situation.

ER
ER (@guest_791042)
July 30, 2019 08:01

Considering the hackers in the Equifax breach got off scot free, and the Equifax employees and executives got off with a slap on the wrist. Sure, they paid out some money, but they can earn more by selling peoples’ information without their consent. I don’t think any executives got fired, much less convicted and sent to prison for a few years.

I’d wager the settlement is part of a civil suit, not a criminal complaint, so nobody’s careers are at risk.

J
J (@guest_791628)
July 31, 2019 12:42
  ER

We’re paying for her lawyer and giving logs to prove insanity. Things are likely going to work out for erratic. She’s hopefully finally going to get the help she deserves after all these years.

Most of the IT department got fired and they’re hiring new at capital one, though.

M
M (@guest_791036)
July 30, 2019 07:27

Credit Monitoring is the new “Going to the Rehab” — and both equally useless. Actually CM is far worse. They’ll spam your emails forever, and you can’t turn them off without opening a new account and paying ransom.

Sam
Sam (@guest_791024)
July 30, 2019 03:12

So this is everybody who applied this way or just a portion “The social security numbers that were stolen were from customers that used their Social Security number as their Employer Identification number in applying for small business credit cards”

Derek
Derek (@guest_791062)
July 30, 2019 08:37

Sounds like the only compromised SS# are from those who applied with it as EIN. Based on the dates, it’s probably likely a high percentage of those individuals are hobbyists and in this community. Getting an EIN is completely free and a good failsafe for this exact reason.

CreditHunter
CreditHunter (@guest_791021)
July 30, 2019 02:37

My capital one card is the oldest card I have. I have unsuccessfully requested a credit limit increase each year for the last 6 years. All other cards I have regularly approve limit increases over the years with zero denials. So I gave up with Crapital One and didn’t bother to even put in a request this year.

Suddenly, this Saturday out of nowhere, I received an email from them stating they automatically increased my limit. Two days later, this data breach comes out. If this wasn’t just a ploy to retain my business since they were about to disclose the breach, then it’s a very strange coincidence.

Mike
Mike (@guest_791006)
July 30, 2019 01:02

Me wiping my tears with all the $125 settlement checks…