HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
Capital One
bd_7216b32347be28d8 · schema v1 · pii pii-v1
Full breach record for Capital One →Capital One filed a supplemental breach notification with the California AG regarding unauthorized access to its network on March 22-23, 2019. An external individual exploited a vulnerability to access consumer and small business application data (names, addresses, DOBs, income) and some transaction data. Approximately 25,850 California residents had SSNs and bank account numbers exposed. Capital One fixed the vulnerability, notified law enforcement, and provided two years of credit monitoring to affected residents.
California clockDiscovered Jul 19, 2019 → Notified Aug 8, 201920d ✓ CA 60-day OK8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b9ef3650c8f0f580California State AGfiled 2019-08-12(30d gap)Candidate
- bd_382af37df42de5b7Delaware State AGfiled 2019-08-08(34d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-150460
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2019
- Raw hash
- b4682333ec32b87134f20fe12157b9271ea269b32c879ce6ad654cf43e3cc633
Reporting entity
- Name
- Capital Onenorm: capital one
- Domain
- capitalone.com
Victim entity
- Name
- Capital Onenorm: capital one
- Domain
- capitalone.com
Incident
- Discovered
- Jul 19, 2019
- Materiality determined
- Sep 11, 2019
- Notification sent
- Aug 8, 2019
- Affected individuals
- 25,850
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified California Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 20d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 19, 2019→ Notified: Aug 8, 201920d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.