Security Experts:

Connect with us

Hi, what are you looking for?



Alleged Capital One Hacker Indicted on Wire Fraud, Computer Data Theft Charges

Paige Thompson, the 33-year-old from Seattle accused of hacking Capital One and 30 other organizations, has been indicted on two counts of wire fraud and computer fraud and abuse.

Paige Thompson, the 33-year-old from Seattle accused of hacking Capital One and 30 other organizations, has been indicted on two counts of wire fraud and computer fraud and abuse.

The Department of Justice announced on Wednesday that Thompson, known online as “erratic,” was indicted by a federal grand jury and will be arraigned on September 5 in the U.S. District Court in Seattle.

Capital One is the only organization that has been named in the indictment, but three other victims have been described as a state agency, a telecommunications conglomerate located outside the U.S., and a public research university in the United States. All of these victims used the services of Amazon Web Services (AWS) — AWS is not specifically named; the indictment references AWS as “the Cloud Computing Company.”

Investigators claim Thompson created a piece of software that allowed her to scan the web for AWS customers that had misconfigured their firewalls, allowing someone to access their servers and the data stored on them. Thompson allegedly not only stole data, but also used the compromised AWS servers to mine cryptocurrency.

Thompson was arrested and her residence was searched in late July. While she did use the Tor network to hide her identity from AWS and the targeted AWS customers, she was not difficult to track down as she openly discussed the hacks on Slack and IRC channels.

Authorities have found no evidence that Thompson sold or disseminated any of the stolen information, but they claim she did use some of the compromised servers to mine cryptocurrency “for her own benefit.”

Thompson faces up to 25 years in prison. A judge ordered her to remain in custody because she is a flight risk and poses a physical danger to herself and others.

AWS recently said that it reached out to customers allegedly targeted by the hacker, but none of them reported any significant issues.

Related: Q&A: What to Know About the Capital One Data Breach

Related: US Wants Woman Accused in Capital One Hack to Stay Locked Up

Written By

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this webinar to learn best practices that organizations can use to improve both their resilience to new threats and their response times to incidents.


Join this live webinar as we explore the potential security threats that can arise when third parties are granted access to a sensitive data or systems.


Expert Insights

Related Content


Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.


Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.


The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.


The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Application Security

PayPal is alerting roughly 35,000 individuals that their accounts have been targeted in a credential stuffing campaign.


No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute to the larger knowledge base.


As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.


A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...