HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Capital One
bd_a4a1cde5ff90a2fc · schema v1 · pii pii-v1
Full breach record for Capital One →Capital One notified California residents that fraudsters used stolen credentials from third-party websites to access Capital One accounts. The breach involved unauthorized login attempts using valid usernames and passwords. Affected data included names, addresses, and partial account numbers. Capital One locked affected accounts, required password resets, and provided two years of free credit monitoring via TransUnion.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-66214
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 6, 2017
- Raw hash
- f8b89a60ec39b12432db6e4b47648c6c6aac8dd0a43050bc6005aa43794597ed
Reporting entity
- Name
- Capital Onenorm: capital one
- Domain
- capitalone.com
Victim entity
- Name
- Capital Onenorm: capital one
- Domain
- capitalone.com
Incident
- Discovered
- Jan 1, 2017
- Materiality determined
- Jan 15, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.