HackingVulnerability ExploitCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumResolved
Capital One
bd_a4cc1dbd0489bada · schema v1 · pii pii-v1
Full breach record for Capital One →Capital One reported a data breach occurring on March 22-23, 2019, involving unauthorized access to customer information. The incident involved an exploit of a public-facing application. Affected data types include PII, identity information, and financial account data. Capital One resolved the issue immediately, cooperated with federal authorities, and offered two years of credit monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539507
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 26, 2021
- Raw hash
- 365a4315305e93a9a24aa3aeb018d9a7c8b5449313f23ecf0d70c4ea1e5e5367
Reporting entity
- Name
- Capital Onenorm: capital one
- Domain
- capitalone.com
Victim entity
- Name
- Capital Onenorm: capital one
- Domain
- capitalone.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Worked with federal authorities
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.