DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Capital One to settle 2019 data breach class action lawsuit for $190 million

Posted on May 13, 2022 by Dissent

Capital One will pay $190 million to resolve claims it jeopardized customer information in a 2019 data breach.

The settlement benefits around 98 million Capital One customers whose information was compromised as part of the 2019 data breach.

Read more at TopClassActions.

This settlement is separate from the $80million penalty Capital One was fined in 2020 by the Office of the Comptroller of the Currency.

One of the significant aspects to this litigation is that  the court ordered the bank to turn over Mandiant’s forensic investigation to plaintiffs, holding that it was not privileged. That decision has already resulted in lawyers for entities rewording their contracts for forensic investigations to make clear that the forensics is not routine scope of work but is being done for litigation defense purposes (which would put it back in the privileged work product framework, it seems).

And for those who didn’t follow the case closely at the time, the person allegedly responsible for the hack, Paige A. Thompson, aka “Erratic,” is a former  Amazon Web Services (AWS) engineer. Thompson was quickly caught, in part, because she bragged on GitHub about a misconfigured web application that she found that enabled her to download Capital One’s data.  In June, 2021, the government added more counts to a superseding indictment. The case is still ongoing, and it appears that the defense lost on its motion to dismiss Counts 2-8. On May 5, the defense tried again, submitting a motion to reconsider the order denying dismissal.

The Capital One attack is one of a number of attacks Thompson was allegedly responsible for.

Readers can find some past coverage of the developments in this case by searching this site for “Capital One” coverage beginning in 2019.

The settlement claim site can be found here.

No related posts.

Category: Financial SectorHackOf NoteU.S.

Post navigation

← Cybercriminal Sentenced To Federal Prison For Decrypting The Credentials Of Thousands Of Computers Across The World And Selling Them On A Dark Web Website
Mission School District suffers IT breach, phishing emails being sent from teachers’ accounts →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Air Force Employee Pleads Guilty to Conspiracy to Disclose Unlawfully Classified National Defense Information
  • UK police arrest four in connection with M&S, Co-op and Harrods cyberattacks (1)
  • At U.S. request, France jails Russian basketball player Daniil Kasatkin on suspicion of ransomware conspiracy
  • Avantic Medical Lab hacked; patient data leaked by Everest Group
  • Integrated Oncology Network victim of phishing attack; multiple locations affected (2)
  • HHS’ Office for Civil Rights Settles HIPAA Privacy and Security Rule Investigation with Deer Oaks Behavioral Health for $225k and a Corrective Action Plan
  • HB1127 Explained: North Dakota’s New InfoSec Requirements for Financial Corporations
  • Credit reports among personal data of 190,000 breached, put for sale on Dark Web; IT vendor fined
  • Five youths arrested on suspicion of phishing
  • Russia Jailed Hacker Who Worked for Ukrainian Intelligence to Launch Cyberattacks on Critical Infrastructure

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • How to Build on Washington’s “My Health, My Data” Act
  • Department of Justice Subpoenas Doctors and Clinics Involved in Performing Transgender Medical Procedures on Children
  • Google Settles Privacy Class Action Over Period Tracking App
  • ICE Is Searching a Massive Insurance and Medical Bill Database to Find Deportation Targets
  • Franklin, Tennessee Resident Sentenced to 30 Months in Federal Prison on Multiple Cyber Stalking Charges
  • On July 7, Gemini AI will access your WhatsApp and more. Learn how to disable it on Android.
  • German court awards Facebook user €5,000 for data protection violations

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.