Ex-AWS engineer convicted of hacking data of 100 mn customers

  • Legal Resolution: Former AWS engineer Paige Thompson was convicted on seven federal counts, including wire fraud, following a breach that compromised 100 million Capital One records.
  • Infrastructure Vulnerability: The breach exploited a Server-Side Request Forgery (SSRF) flaw, prompting AWS to mandate IMDSv2 as the global industry standard for cloud metadata security.
  • Financial Penalties: Capital One faced an $80 million regulatory fine and a $190 million class-action settlement, marking it as one of the costliest misconfigurations in cloud history.

The thin line between elite technical proficiency and criminal exploitation was laid bare in a Seattle courtroom as the legal saga of the Capital One data breach reached its definitive conclusion. Paige Thompson, a former Amazon Web Services (AWS) engineer, has been convicted for her role in an intrusion that didn’t just expose the private data of 100 million people, but fundamentally altered how the world perceives cloud security and the “insider threat” profile.

The Final Verdict: Accountability for a Landmark Breach

Following a high-stakes trial, Thompson was found guilty of wire fraud, five counts of unauthorized access to a protected computer, and damaging a protected computer. While the defense characterized her as an “ethical hacker” identifying systemic flaws, the prosecution successfully argued that her motives were rooted in ego and personal gain. Evidence presented during the trial showed Thompson not only exfiltrated data but also hijacked server power to mine cryptocurrency for her own benefit.

The scale of the theft remains a sobering benchmark even in 2026. The 2019 breach involved the names, addresses, credit scores, and social security numbers of millions of applicants. Following her conviction, the legal system focused on the precedent set by her actions. Although she was acquitted of aggravated identity theft, the wire fraud conviction carried significant weight, highlighting the federal government’s aggressive stance on cyber-extortion and data theft.

Note: While Thompson was convicted for the Capital One breach, modern security teams are now seeing a shift. Today, hackers target security experts with fake crypto lures using social engineering rather than the infrastructure misconfigurations Thompson pioneered.

A Technical Autopsy: The SSRF Flaw and the AWS Response

The technical core of the hack involved a Server-Side Request Forgery (SSRF) attack. Thompson exploited a misconfigured web application firewall (WAF) to gain access to the AWS Metadata Service. This allowed her to retrieve temporary credentials with excessive permissions, enabling the mass exfiltration of data stored in S3 buckets.

In response to this breach, AWS accelerated the deployment of IMDSv2 (Instance Metadata Service Version 2). This update requires a session-oriented authentication flow, effectively neutralizing the specific SSRF method Thompson utilized. For organizations today, understanding these legacy vulnerabilities is critical, especially when learning how to tell if your AI account is hacked or if your underlying cloud infrastructure remains exposed to similar lateral movement.

The Financial and Regulatory Fallout

The consequences for Capital One were swift and severe. The Office of the Comptroller of the Currency (OCC) issued an $80 million civil money penalty, citing the bank’s failure to establish effective risk assessment processes before migrating workloads to the cloud. Furthermore, the company finalized a Department of Justice-verified $190 million settlement to resolve class-action litigation from affected customers.

Impact Metric Details
Total Victims 100 Million (US) / 6 Million (Canada)
Regulatory Fine $80 Million (OCC)
Legal Settlement $190 Million Class-Action
Primary Attack Vector SSRF via Misconfigured WAF

The Legacy of Thompson: From Infrastructure to Identity

As we navigate the cybersecurity landscape of 2026, the Paige Thompson conviction serves as a pivotal bridge between the “Wild West” era of cloud adoption and today’s “Zero Trust” mandates. While Thompson exploited architectural flaws, contemporary breaches—like the massive Snowflake and Ticketmaster leaks of 2024—have shifted the focus toward identity-based attacks and credential theft.

The industry has moved toward automated remediation, but the human element remains the most volatile variable. Much like how CareCloud begins to notify hundreds of thousands of victims in recent breach cycles, the Capital One incident forced a reckoning regarding transparency and the speed of disclosure. Thompson’s conviction wasn’t just a win for federal prosecutors; it was a loud signal to the tech community that “bragging” about unauthorized access is no longer viewed as a harmless subculture, but as a high-stakes felony with decade-long consequences.

“She wanted data, she wanted money, and she wanted to brag,” stated Assistant US Attorney Andrew Friedman. In the digital age, that trio of motives continues to drive the most significant threats to global privacy.

More From Category

More Stories Today