{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T09:50:01Z","timestamp":1785577801615,"version":"3.56.0"},"reference-count":63,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T00:00:00Z","timestamp":1667779200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2023,2,28]]},"abstract":"<jats:p>The 2019 Capital One data breach was one of the largest data breaches impacting the privacy and security of personal information of over a 100 million individuals. In most reports about a cyberattack, you will often hear that it succeeded because a single employee clicked on a link in a phishing email or forgot to patch some software, making it seem like an isolated, one-off, trivial problem involving maybe one person, committing a mistake or being negligent. But that is usually not the complete story. By ignoring the related managerial and organizational failures, you are leaving in place the conditions for the next breach. Using our Cybersafety analysis methodology, we identified control failures spanning control levels, going from rather technical issues up to top management, the Board of Directors, and Government regulators. In this analysis, we reconstruct the Capital One hierarchical cyber safety control structure, identify what parts failed and why, and provide recommendations for improvements. This work demonstrates how to discover the true causes of security failures in complex information systems and derive systematic cybersecurity improvements that likely apply to many other organizations. It also provides an approach that individuals can use to evaluate and better secure their organizations.<\/jats:p>","DOI":"10.1145\/3546068","type":"journal-article","created":{"date-parts":[[2022,7,7]],"date-time":"2022-07-07T11:26:56Z","timestamp":1657193216000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":57,"title":["A Systematic Analysis of the Capital One Data Breach: Critical Lessons Learned"],"prefix":"10.1145","volume":"26","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5426-0778","authenticated-orcid":false,"given":"Shaharyar","family":"Khan","sequence":"first","affiliation":[{"name":"Sloan School of Management, Massachusetts Institute of Technology, Cambridge"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4402-558X","authenticated-orcid":false,"given":"Ilya","family":"Kabanov","sequence":"additional","affiliation":[{"name":"Sloan School of Management, Massachusetts Institute of Technology, Cambridge"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9531-8665","authenticated-orcid":false,"given":"Yunke","family":"Hua","sequence":"additional","affiliation":[{"name":"Sloan School of Management, Massachusetts Institute of Technology, Cambridge"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9240-2573","authenticated-orcid":false,"given":"Stuart","family":"Madnick","sequence":"additional","affiliation":[{"name":"Sloan School of Management, Massachusetts Institute of Technology, Cambridge"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,11,7]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"B. Kammel D. Pogkas and M. Benhamou. 2020. These are the worst cyber attacks ever. Retrieved from https:\/\/www.bloomberg.com\/graphics\/corporate-hacks-cyber-attacks\/."},{"key":"e_1_3_2_3_2","unstructured":"Capital One. Information on the Capital One Cyber Incident. Retrieved on 24-July-2022 https:\/\/www.capitalone.com\/facts2019\/."},{"key":"e_1_3_2_4_2","unstructured":"U.S. Department of Justice US District Court for the Western District of Washington at Seattle. United States of America vs. Paige A. Thompson a\/k\/a `erratic'. Case No. MJ19-0344 Filed 07\/27\/19 [Online]. Retrieved on 24-July-2022 https:\/\/www.justice.gov\/usao-wdwa\/press-release\/file\/1188626\/."},{"key":"e_1_3_2_5_2","unstructured":"I. Kabanov and S. Madnick. 2021. Applying the Lessons from the Equifax Cybersecurity Incident to Build a Better Defense. MIS Quarterly Executive 20 2 Article 4 (2021). https:\/\/aisel.aisnet.org\/misqe\/vol20\/iss2\/4."},{"key":"e_1_3_2_6_2","unstructured":"R. Walikar. 2020. An SSRF privileged AWS keys and the Capital One breach. Appsecco. Retrieved from https:\/\/blog.appsecco.com\/an-ssrf-privileged-aws-keys-and-the-capital-one-breach-4c3c2cded3af."},{"key":"e_1_3_2_7_2","unstructured":"J. Villa. 2020. The Capital One breach: Did the technology or the process fail? Retrieved from https:\/\/www.guidepointsecurity.com\/how-aws-best-practices-hurt-capital-one\/."},{"key":"e_1_3_2_8_2","article-title":"A case study of the Capital One data breach","author":"Novaes Neto N.","year":"2020","unstructured":"N. Novaes Neto, S. E. Madnick, A. Moraes, G. de Paula, and N. Malara Borges. 2020. A case study of the Capital One data breach. SSRN Electron. J. (Mar. 2020).","journal-title":"SSRN Electron. J."},{"key":"e_1_3_2_9_2","doi-asserted-by":"crossref","unstructured":"N. Leveson. 2004. A new accident model for engineering safer systems. Safety Science 42 4 (2004) 237--270. https:\/\/doi.org\/10.1016\/S0925-7535(03)00047-X.","DOI":"10.1016\/S0925-7535(03)00047-X"},{"key":"e_1_3_2_10_2","unstructured":"IEEE Transactions on Dependable and Secure Computing"},{"key":"e_1_3_2_11_2","volume-title":"Engineering a Safer World","author":"Leveson N. G.","year":"2018","unstructured":"N. G. Leveson. 2018. Engineering a Safer World. The MIT Press."},{"key":"e_1_3_2_12_2","unstructured":"H. Salim and S. Madnick. 2016. Cyber Safety: A Systems Theory Approach to Managing Cyber Security Risks-Applied to TJX Cyber Attack. Retrieved on 24-July-2022 http:\/\/web.mit.edu\/smadnick\/www\/wp\/2016-09.pdf."},{"key":"e_1_3_2_13_2","unstructured":"Capital One. 2020. 2019 Capital One cyber incident. What happened. Retrieved from https:\/\/www.capitalone.com\/facts2019\/."},{"key":"e_1_3_2_14_2","unstructured":"United States of America Department of the Treasury Office of the Comptroller of the Currency (OCC) ``Consent Order for the Assessment of a Civil Money Penalty'' Case No. AA-EC-20-51. Retrievd on 24-July-2022 https:\/\/www.occ.gov\/static\/enforcement-actions\/ea2020-036.pdf."},{"key":"e_1_3_2_15_2","unstructured":"A. Andriotis. 2020. Capital One senior security officer being moved to new role. Wall Street Journal . Retrieved from https:\/\/www.wsj.com\/articles\/capital-one-senior-security-officer-being-moved-to-new-role-11573144068."},{"key":"e_1_3_2_16_2","unstructured":"J. Shukla. 2020. Understanding the Capital One attack. When WAFs Fail. Retrieved from https:\/\/www.k2io.com\/understanding-capital-one-attack\/."},{"key":"e_1_3_2_17_2","unstructured":"G. Steel. 2020. The Capital One breach and cloud encryption. Cryptosense. Retrieved from https:\/\/cryptosense.com\/blog\/the-capital-one-breach-and-cloud-encryption\/."},{"key":"e_1_3_2_18_2","unstructured":"J. Stella. 2020. A technical analysis of the Capital One cloud misconfiguration breach. Retrieved from https:\/\/www.fugue.co\/blog\/a-technical-analysis-of-the-capital-one-cloud-misconfiguration-breach."},{"key":"e_1_3_2_19_2","unstructured":"C. Morrison. 2020. The technical side of the capitol one AWS security breach. Retrieved from https:\/\/start.jcolemorrison.com\/the-technical-side-of-the-capital-one-aws-security-breach\/."},{"key":"e_1_3_2_20_2","unstructured":"B. Krebs. 2020. What we can learn from the Capital One hack \u2014 Krebs on security. Retrieved from https:\/\/krebsonsecurity.com\/2019\/08\/what-we-can-learn-from-the-capital-one-hack\/#more-48424."},{"key":"e_1_3_2_21_2","unstructured":"E. Flitter and K. Weise. 2020. Capital One data breach compromises data of over 100 million. The New York Times . Retrieved from https:\/\/www.nytimes.com\/2019\/07\/29\/business\/capital-one-data-breach-hacked.html."},{"key":"e_1_3_2_22_2","unstructured":"AWS. 2021. Capital One enterprise case study\u2014Amazon web services (AWS). Retrieved from https:\/\/aws.amazon.com\/solutions\/case-studies\/capital-one-enterprise\/."},{"key":"e_1_3_2_23_2","unstructured":"US Attorney's Office. 2021. Bank employee charged with stealing more than $100K from customer accounts. USAO-CT. Department of Justice. Retrieved from https:\/\/www.justice.gov\/usao-ct\/pr\/bank-employee-charged-stealing-more-100k-customer-accounts.."},{"key":"e_1_3_2_24_2","unstructured":"Capital One. 2021. Capital One reports inside job data breach. Retrieved from https:\/\/oag.ca.gov\/system\/files\/CAAGNoticeRemediationLetter41952117_0.pdf."},{"key":"e_1_3_2_25_2","unstructured":"C. Folini. 2020. \u201cChristian Folini on Twitter:\u201d.@briankrebs explains the @CapitalOne breach as a Server-Side Request Forgery due to a misconfigured #ModSecurity. I'm intrigued but I can't see how you could configure the #WAF for #SSRF \u2013 and I wrote the #ModSecurity hand. Retrieved from https:\/\/mobile.twitter.com\/ChrFolini\/status\/1157533808402620416."},{"key":"e_1_3_2_26_2","unstructured":"Alberto Wilson and G. Gabarrin. 2022. SSRF's up! Real world server-side request forgery (SSRF) Shorebreak Security\u2014experts in information security testing. Retrieved from https:\/\/www.shorebreaksecurity.com\/blog\/ssrfs-up-real-world-server-side-request-forgery-ssrf\/."},{"key":"e_1_3_2_27_2","unstructured":"A. Ng. 2021. Amazon tells senators it isn't to blame for Capital One breach. Cnet. Retrieved from https:\/\/www.cnet.com\/news\/amazon-tells-senators-it-isnt-to-blame-for-capital-one-breach\/."},{"key":"e_1_3_2_28_2","unstructured":"T. Spring. 2021. Misconfigured reverse proxy servers spill credentials. Threatpost. Retrieved from https:\/\/threatpost.com\/misconfigured-reverse-proxy-servers-spill-credentials\/132085\/."},{"key":"e_1_3_2_29_2","unstructured":"A. Tiurin. 2021. A fresh look on reverse proxy related attacks | acunetix. Acunetix. Retrieved from https:\/\/www.acunetix.com\/blog\/articles\/a-fresh-look-on-reverse-proxy-related-attacks\/."},{"key":"e_1_3_2_30_2","unstructured":"K. Narayan. 2020. How an attacker could use instance metadata to breach your app in AWS. McAfee Blogs. Retrieved from https:\/\/www.mcafee.com\/blogs\/enterprise\/cloud-security\/how-an-attacker-could-use-instance-metadata-to-breach-your-app-in-aws\/."},{"key":"e_1_3_2_31_2","unstructured":"T. Pohl and B. Williams. 2021. Hacking the cloud: Exploiting AWS misconfigurations. Retrieved from https:\/\/www.youtube.com\/watch?v=0PhKK-GHgBI."},{"key":"e_1_3_2_32_2","unstructured":"Capital One. 2019. Capital One Announces Data Security Incident. Retrieved on 24-July-2022 https:\/\/www.capitalone.com\/about\/newsroom\/capital-one-announces-data-security-incident\/."},{"key":"e_1_3_2_33_2","unstructured":"E. M. Hutchins M. J. Cloppert and R. M. Amin. 2011. Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains. Leading Issues in Information Warfare & Security Research vol. 1. Retrieved on 24-July-2022 https:\/\/www.lockheedmartin.com\/content\/dam\/lockheed-martin\/."},{"key":"e_1_3_2_34_2","unstructured":"Cloudflare. 2020. What is a WAF? Web application firewall explained. Cloudflare. Retrieved from https:\/\/www.cloudflare.com\/learning\/ddos\/glossary\/web-application-firewall-waf\/."},{"key":"e_1_3_2_35_2","unstructured":"J. Davis. 2020. Capital One CIO: We're a software company. Information Week . Retrieved from https:\/\/www.informationweek.com\/strategic-cio\/executive-insights-and-innovation\/capital-one-cio-were-a-software-company\/d\/d-id\/1333457?"},{"key":"e_1_3_2_36_2","unstructured":"PCI Security Standards Council Payment Card Industry Data Security Standard (PCI DSS). 2018. Requirements and Security Assessment Procedures - Requirement 6.6 Version 3.2.1. Retrieved on 24-July-2022 https:\/\/www.pcisecuritystandards.org\/document_library\/?category=pcidss&document=pci_dss."},{"key":"e_1_3_2_37_2","unstructured":"S. Peters. 2019. What's in a WAF? Dark Reading Article November 20 2019 [Online]. Retrieved 21-Dec-2020 https:\/\/www.darkreading.com\/edge\/theedge\/whats-in-a-waf-\/b\/d-id\/1336402."},{"key":"e_1_3_2_38_2","unstructured":"G. Otto. 2020. What Capital One's cybersecurity team did (and did not) get right. Cyberscoop. Retrieved from https:\/\/www.cyberscoop.com\/capital-one-cybersecurity-data-breach-what-went-wrong\/."},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2016.19"},{"key":"e_1_3_2_40_2","unstructured":"G. Mateaki. 2020. PCI 6.6: Why you need a web application firewall and network firewall. Retrieved from https:\/\/www.securitymetrics.com\/blog\/pci-66-why-you-need-web-application-firewall-and-network-firewall."},{"key":"e_1_3_2_41_2","article-title":"Capital One cyber staff raised concerns before hack","author":"Andriotis A.","year":"2020","unstructured":"A. Andriotis and R. L. Ensign. 2020. Capital One cyber staff raised concerns before hack. The Wall Street Journal. Retrieved from https:\/\/www.wsj.com\/articles\/capital-one-cyber-staff-raised-concerns-before-hack-11565906781.","journal-title":"The Wall Street Journal"},{"key":"e_1_3_2_42_2","unstructured":"J. Murdock. 2021. Amazon refuses blame for Capital One data breach says its cloud services were \u201cnot compromised in any way.\u201d Retrieved from https:\/\/www.newsweek.com\/amazon-capital-one-hack-data-leak-breach-paige-thompson-cybercrime-1451665."},{"key":"e_1_3_2_43_2","unstructured":"AWS. 2021. Shared responsibility model\u2014Amazon Web Services (AWS). Retrieved from https:\/\/aws.amazon.com\/compliance\/shared-responsibility-model\/."},{"key":"e_1_3_2_44_2","unstructured":"L. O'Donnell. 2021. Is AWS liable in capital one breach?. Threatpost. Retrieved from https:\/\/threatpost.com\/capital-one-breach-senators-aws-investigation\/149567\/."},{"key":"e_1_3_2_45_2","unstructured":"AWS. 2021. Add defense in depth against open firewalls reverse proxies and SSRF vulnerabilities with enhancements to the EC2 Instance Metadata Service. AWS Security Blog. Retrieved from https:\/\/aws.amazon.com\/blogs\/security\/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service\/."},{"key":"e_1_3_2_46_2","unstructured":"The Duquesne Group. 2021. Mission AWS 2019: \u201cEnable our Customers to Innovate.\u201d Retrieved from https:\/\/www.duquesnegroup.com\/Mission-AWS-2019-Enable-our-Customers-to-Innovate_a347.html."},{"key":"e_1_3_2_47_2","unstructured":"S. Harris. 2021. Capital One breach\u2014Ramblings of a Unix geek. Retrieved from https:\/\/www.sweharris.org\/post\/2019-08-21-capital-one\/."},{"key":"e_1_3_2_48_2","unstructured":"N. Eide. 2020. Capital One's public cloud strategy at odds with industry. CIO Dive. Retrieved from https:\/\/www.ciodive.com\/news\/capital-ones-public-cloud-strategy-at-odds-with-industry\/547245\/."},{"key":"e_1_3_2_49_2","unstructured":"Capital One. 2021. Capital One annual report 2018. Retrieved from https:\/\/ir-capitalone.gcs-web.com\/static-files\/04c57bd9-b351-418c-9f18-ed91d4bfad23."},{"key":"e_1_3_2_50_2","unstructured":"Capital One. 2021. Capital One annual report 2019. Retrieved from https:\/\/ir-capitalone.gcs-web.com\/static-files\/2f0f821a-0db0-4eab-9895-63013c4e59c2."},{"key":"e_1_3_2_51_2","unstructured":"J. Surane and L. Nguyen. 2021. Capital One touted the data cloud's safety. Then a hacker breached it. Los Angeles Times . Retrieved from https:\/\/www.latimes.com\/business\/story\/2019-07-30\/capital-one-cloud-safety-hacker-breach."},{"key":"e_1_3_2_52_2","unstructured":"Capital One. 2022. Press Release. Capital One. Retrieved from https:\/\/www.capitalone.com\/about\/newsroom\/capital-one-announces-data-security-incident\/."},{"key":"e_1_3_2_53_2","unstructured":"ISACA\/Protiviti. 2019. Today's Toughest Challenges in IT Audit: Tech Partnerships Talent Transformation.Audit Benchmarking Study [Online]. Retrieved on 24-July-2022 https:\/\/www.protiviti.com\/US-en\/insights\/it-audit-benchmarking-survey."},{"key":"e_1_3_2_54_2","unstructured":"Federal Reserve Education. 2021. Banking supervision. Retrieved from https:\/\/www.federalreserveeducation.org\/about-the-fed\/structure-and-functions\/banking-supervision."},{"key":"e_1_3_2_55_2","unstructured":"Comptroller of the Currency Federal Reserve System Federal Deposit Insurance Corporation and Thrift Supervision Office. 2000. Federal register: Interagency guidelines establishing standards for safeguarding customer information and rescission of year 2000 standards for safety and soundness. 65 FR 39471 26-Jun-2000. Retrieved from https:\/\/www.federalregister.gov\/documents\/2000\/06\/26\/00-15798\/interagency-guidelines-establishing-standards-for-safeguarding-customer-information-and-rescission."},{"key":"e_1_3_2_56_2","doi-asserted-by":"crossref","unstructured":"A. Marotta and S. Madnick. 2020. Analyzing the Interplay Between Regulatory Compliance and Cybersecurity (Revised). Working Paper CISL# 2020-15 Available at SSRN: https:\/\/ssrn.com\/abstract=3569902 or http:\/\/dx.doi.org\/10.2139\/ssrn.3569902","DOI":"10.2139\/ssrn.3569902"},{"key":"e_1_3_2_57_2","unstructured":"C. Feeney. 2017. Testimony of Christopher Feeney before the US Senate Committee on Homeland Security & Govt. Affairs -- `Cybersecurity Regulation Harmonization' Financial Services Roundtable (FSR) - BITS 2017. Retrieved on 24-July-2022 https:\/\/www.hsgac.senate.gov\/imo\/media\/doc\/Testimony-Feeney-2017-06-21.pdf"},{"key":"e_1_3_2_58_2","unstructured":"Kaspersky. 2017. Banks spend on IT security is 3x higher than non-financial organizations. Kaspersky. Retrieved from https:\/\/www.kaspersky.com\/about\/press-releases\/2017_banks-spends."},{"key":"e_1_3_2_59_2","unstructured":"N. Nelson. 2008. A STAMP Analysis of the Lex Comair 5191 Accident. Master's Thesis Lund University Sweden. [Online]. Retrieved on 24-July-2022 http:\/\/sunnyday.mit.edu\/papers\/nelson-thesis.pdf."},{"key":"e_1_3_2_60_2","unstructured":"P. S. Nelson. 2008. A STAMP Analysis of the Lex Comair 5191 Accident. Master's Thesis Lund University Sweden. [Online]. Retrieved on 24-July-2022 http:\/\/sunnyday.mit.edu\/papers\/nelson-thesis.pdf."},{"key":"e_1_3_2_61_2","unstructured":"S. Malmquist N. Leveson G. Larard J. Perry and D. Straker. Increasing Learning from Accidents -- A Systems Approach illustrated by the UPS Flight 1354 CFIT Accident. [Online]. Retrieved on 24-July-2022 http:\/\/sunnyday.mit.edu\/UPS-CAST-Final.pdf."},{"key":"e_1_3_2_62_2","unstructured":"N. G. Leveson. 2016. CAST Analysis of the Shell Moerdijk Accident. [Online]. Retrieved on 24-July-2022 http:\/\/sunnyday.mit.edu\/shell-moerdijk-cast.pdf."},{"key":"e_1_3_2_63_2","unstructured":"N. Leveson M. Daouk N. Dulac and K. Marais. Applying STAMP in Accident Analysis. [Online]. Retrieved on 24-July-2022 https:\/\/shemesh.larc.nasa.gov\/iria03\/p13-leveson.pdf."},{"key":"e_1_3_2_64_2","unstructured":"N. G. Leveson and M. Joel Cutcher-Gershenfeld. 2004. What System Safety Engineering can learn from the Columbia Accident. [Online]. Retrieved on 24-July-2022 http:\/\/sunnyday.mit.edu\/papers\/issc04-final.pdf."}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3546068","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3546068","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:30:19Z","timestamp":1750188619000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3546068"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,7]]},"references-count":63,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2023,2,28]]}},"alternative-id":["10.1145\/3546068"],"URL":"https:\/\/doi.org\/10.1145\/3546068","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"value":"2471-2566","type":"print"},{"value":"2471-2574","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,7]]},"assertion":[{"value":"2021-05-11","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-06-22","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-11-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}