Here are the pages of the report that make me upset:
- Page 6, paragraph 10 : "A firewall misconfiguration permitted commands to reach and be executed by that server, which enabled access to folders or buckets of data in Capital One's storage space at the Cloud Computing Company"
- Page 8, paragraph 14: "According to Capital One, the data copied from Capital One's data folders or buckets includes primarily data related to credit card applications. Although some of the information in those applications (such as SSN) has been tokenized or encrypted, other information including applicants' names, addresses, dates of birth and information regarding their credit history has not been tokenized. According to Capital One, the data includes data regarding large numbers of applications, likely tens of millions of applications. According to Capital One that dta includes approximately 120,000 SSN and approximately 77,000 bank account numbers.