Capital One's 2019 Data Breach Was a Misconfigured IAM Role, Not Just an SSRF Flaw
In March 2019, an attacker exploited a misconfigured web application firewall at Capital One to perform a server-side request forgery, retrieving AWS instance metadata credentials via the IMDSv1 service at 169.254.169.254. The critical factor was not the SSRF itself but the overly permissive IAM role attached to the firewall instance, which granted read access to S3 buckets across the entire account, exposing personal data of 106 million people. The breach went undetected until July 17, 2019, when an outside party alerted Capital One through its responsible disclosure channel. Capital One faced an $80 million civil penalty from the OCC in August 2020 and a $190 million class action settlement, with regulators citing failures in risk assessment and internal controls. The incident remains a cautionary study in the principle of least privilege — the encryption in place was rendered ineffective because the same credentials used to access the data could also decrypt it.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in