HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
Capital One
bd_b9ef3650c8f0f580 · schema v1 · pii pii-v1
Full breach record for Capital One →Capital One notified the California AG of a breach occurring March 22-23, 2019, discovered July 19, 2019. An external individual exploited a vulnerability to access credit card applicant and customer data, including names, SSNs, and bank account numbers. 17,807 California residents were notified. Capital One fixed the vulnerability, worked with law enforcement, and provided two years of credit monitoring via TransUnion.
California clockDiscovered Jul 19, 2019 → Notified Aug 8, 201920d ✓ CA 60-day OK24 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_382af37df42de5b7Delaware State AGfiled 2019-08-08(4d gap)Verified
- bd_7216b32347be28d8California State AGfiled 2019-09-11(30d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-149653
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 12, 2019
- Raw hash
- 4ac22ebbb7ebc6f8eb23f99ec649fa1f79e8cd39f2883cfc930fa72fa585cb8c
Reporting entity
- Name
- Capital Onenorm: capital one
- Domain
- capitalone.com
Victim entity
- Name
- Capital Onenorm: capital one
- Domain
- capitalone.com
Incident
- Discovered
- Jul 19, 2019
- Materiality determined
- —
- Notification sent
- Aug 8, 2019
- Affected individuals
- 17,807
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified California Attorney General's Office pursuant to Security Breach Notice Act, Cal. Civ. Code §1798.82
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 20d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 19, 2019→ Notified: Aug 8, 201920d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.