MisuseFinancial ServicesFinancePrivilege AbuseCustomer Data InvolvedDelayed DiscoveryData ExfiltratedPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTBEHAVIORMediumResolved
Capital One
bd_a222a030b4587ab5 · schema v1 · pii pii-v1
Full breach record for Capital One →A former Capital One employee accessed Capital One 360 customer account information without authorization between January 27, 2017 and April 20, 2017. Exposed data included names, addresses, account numbers, phone numbers, transaction history, dates of birth, and Social Security Numbers. A total of 586 California residents were notified in two waves (July and September 2017). The employee was terminated. Capital One notified the California AG in August 2018.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-138718
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 9, 2018
- Raw hash
- d25c399b99fb137ae66cc2ab85b753c59122e95efd668b3db62290b8b00907fb
Reporting entity
- Name
- Capital Onenorm: capital one
- Domain
- capitalone.com
Victim entity
- Name
- Capital Onenorm: capital one
- Domain
- capitalone.com
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jul 28, 2017
- Affected individuals
- 0
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTBEHAVIOR
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid AccountsT1530 Data from Cloud Storage Object
- Threat actor
- Internal
- Regulator citations
- Notified California Office of the Attorney General (letter dated August 9, 2018)
- Initial access
- insider_action
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.