Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Congress Wants Capital One, Amazon to Explain Data Breach

Leaders of House and Senate committees want Capital One and Amazon to explain to Congress how a hacker accessed personal information from more than 100 million Capital One credit card customers and applicants.

Leaders of House and Senate committees want Capital One and Amazon to explain to Congress how a hacker accessed personal information from more than 100 million Capital One credit card customers and applicants.

The incident was the latest massive data breach at a large company.

Ohio Rep. Jim Jordan, the top Republican on the House Oversight and Reform Committee, asked for a staff-level briefing by Aug 15 on the breach that was reported late Monday.

The chairman of the Senate Banking, Housing and Urban Affairs Committee also said the committee will look into the matter. Sen. Mike Crapo, R-Idaho, plans legislation that would establish new data safeguards for consumers.

“I have concerns about all aspects of this,” Crapo told reporters this week. “We want to understand how this happened, how other breaches happened … and we want to know how vulnerabilities (appear) in systems and figure out what we must do to deal with them at a policy level.”

The head of the House Financial Services Committee, Rep. Maxine Waters, D-Calif., has also organized a briefing from Capital One for Democratic and Republican staff members, according to congressional aides.

“As this is not the first incident in which Capital One’s customer data was exposed, we need to understand what bank regulators have been doing to ensure that this bank and other banks have strong cybersecurity policies and practices,” Waters said. She plans legislation to improve oversight of the cybersecurity of financial institutions.

In a letter Thursday to Amazon CEO Jeff Bezos, Jordan and other Republicans on the House Oversight panel note that Capital One data was stored on a cloud service provided by Amazon Web Services. The suspected hacker , Paige Thompson, is a former Amazon software engineer.

Advertisement. Scroll to continue reading.

FBI agents arrested Thompson on Monday for allegedly obtaining personal information from more than 100 million Capital One credit applications, including roughly 140,000 Social Security numbers and 80,000 bank account numbers. There is no evidence the data was sold or distributed to others.

Rep. Elijah Cummings, chairman of the House Oversight and Reform Committee, said the committee has a long and bipartisan history of investigating data breaches in the government and private sector. Cummings, D-Md., said he looks forward to hearing more information about the data breach from Capital One and the company’s response.

A spokesman for McLean, Virginia-based Capital One said in a statement that the company has “proactively engaged in discussions with lawmakers and elected officials since the arrest of the perpetrator of this cyber incident on Monday and will continue to do so.”

A spokesman for Amazon did not immediately respond to requests for comment.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

Incident Response

Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.

Data Breaches

GoTo said an unidentified threat actor stole encrypted backups and an encryption key for a portion of that data during a 2022 breach.

Application Security

GitHub this week announced the revocation of three certificates used for the GitHub Desktop and Atom applications.

Incident Response

Meta has developed a ten-phase cyber kill chain model that it believes will be more inclusive and more effective than the existing range of...

Cloud Security

VMware described the bug as an out-of-bounds write issue in its implementation of the DCE/RPC protocol. CVSS severity score of 9.8/10.