CASE DOSSIER
convicted
U.S. v. Paige Thompson (Capital One Cloud Breach)
Docket: 2:19-cr-00159 Court: U.S. District Court for the Western District of Washington Opened: 2019-07-29 Sector: Financial Services, Cloud Computing
Key Facts
Status
CONVICTED
Legal disposition
Loss Amount
$270.0 million
Capital One incurred $270 million in customer notifications, legal settlements, and regulatory fines.
Techniques
3
Verified mappings
Defendants
1
Named in charges
- Legal Status: CONVICTED in U.S. District Court for the Western District of Washington.
- Primary Target Sector: Financial Services, Cloud Computing.
- Documented Financial Loss: $270.0 million.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Former Seattle cloud engineer who identified misconfigured web application firewalls to gain unauthorized access to Capital One's Amazon Web Services storage buckets, exfiltrating 106 million customer credit card applications.
Procedural & Incident Timeline
2019-07-29 arrest
FBI agents arrest Thompson at her residence in Seattle.
2022-06-17 verdict
Jury finds Thompson guilty of wire fraud and six counts of unauthorized access to a protected computer.
2022-10-04 sentencing
Sentenced to time served and five years of supervised release with restitution ordered.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Paige Adele Thompson | United States | convicted | Pending | None | Perpetrator of Capital One cloud data breach; convicted of wire fraud and computer intrusion. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Thompson sent crafted HTTP requests exploiting a Server-Side Request Forgery (SSRF) flaw in a misconfigured open-source ModSecurity WAF." | Indictment ¶ 9, Page 4 | reviewed |
| T1078 | Valid Accounts Defense Evasion | "Obtained temporary security credentials from the AWS EC2 instance metadata service to access private S3 storage buckets." | Trial Transcript Day 3, Page 54 | reviewed |
| T1083 | File and Directory Discovery Discovery | "Thompson ran automated aws-s3 listing commands to enumerate bucket contents across victim customer directories." | Indictment ¶ 12, Page 6 | reviewed |
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Paige Thompson (Capital One Cloud Breach), No. 2:19-cr-00159 (U.S. District Court for the Western District of Washington 2019), https://cyberattackcaselibrary.pages.dev/cases/us-v-thompson-capital-one-breach/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-thompson-capital-one-breach" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>