Interestingly nobody would be fined by the regulator had the misconfiguration not been discovered by someone stupid enough to to post about it with their real name, organised criminals would have been smarter about it.
The misconfiguration on a “firewall” sounds like AWS is deep into the capital one org tightly controlling the narrative. Whilst at the end of the day it was an EC2 that had access to all the accounts S3 buckets that was configured to pass out its role token to anyone that asked and the bucket itself had no protection against outside access with a compromised key. This to me sounds like absolute negligence for an FI and rightfully deserves the fine. Back when this attack was done the AWS service made it very complex to mitigate against this type of attack and since then AWS have scrambled to release a bunch of “features” to fix this like Aws:calledvia , s3:resourceaccount condition key, s3 block public access came out just before attack was made public I am sure there were others but this is what I can recall.