Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Capital One Notifies More Clients Of SSNs Exposed In 2019 Data Breach

Capital One Notifies More Clients Of SSNs Exposed In 2019 Data Breach

Image: Vinayak Sharma

US bank Capital One notified additional customers that their Social Security numbers were exposed in a data breach announced in July 2019.

The day the breach was disclosed, the Department of Justice arrested and indicted the suspected hacker, former Amazon Web Services (AWS) employee Paige Thompson, who posted about stealing data on GitHub after infiltrating Capital One’s AWS cloud servers.

Thompson allegedly stole over 100 million people’s personal information, including names, email addresses, dates of birth, transaction data, credit scores, payment history, balances, and for some, linked bank accounts and social security numbers.

The suspect also gained access to roughly 140,000 Social Security numbers and around 80,000 linked bank account numbers of credit card customers. Thompson also used the compromised servers to mine for cryptocurrency, according to the indictment.

Capital One was not the only organization hacked by the attacker, with media reporting that the list of breached companies might also include Vodafone, Ford, Unicredit, the Ohio Department of Transportation, and Michigan State University.

Also Read: PDPA Singapore Guidelines: 16 Key Concepts For Your Business

New exposed customer information discovered

While the breach notification letters might seem out of place almost two years after the incident, they were prompted by new findings while analyzing data stolen during the 2019 security breach.

However, after re-analyzing the stolen data using new tools, the bank discovered that the hacker did gain access and stole some of its customers’ SSNs.

“Immediately after the 2019 data security incident, we conducted an analysis with the assistance of an external third-party expert to determine what information was accessed by the unauthorized individual,” Capital One said. “At that time, we did not identify you as one of the individuals whose Social Security number was part of the accessed data.”

“Recently, Capital One re-examined the files that were impacted by the 2019 data security incident using new and more advanced tools. As part of this analysis, we determined that your Social Security number was among the data to which the unauthorized individual gained access.”

According to Capital One, the bank notified customers of this additional exposed personal information even though there is no evidence that it was disseminated or used for fraud.

Fines and estimated losses

Capital One said that the incident is expected to generate costs of $100 to $150 million due to customer notifications, free credit monitoring services, security improvement costs, and legal fees.

However, the bank also added that it had cybersecurity insurance that will cover up to $400 million with a $10 million deductible.

Last year, Capital One was fined $80 million by the Office of the Comptroller of the Currency (OCC), the US banking regulator, for its failure to protect its customers’ personal and financial information.

Also Read: Data Protection Officer Singapore | 10 FAQs

“The OCC took these actions based on the bank’s failure to establish effective risk assessment processes prior to migrating significant information technology operations to the public cloud environment and the bank’s failure to correct the deficiencies in a timely manner,” OCC said.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us