← All enforcement actions
GLBABank Service Co ActBanking

Capital One$80M + $190M class GLBA fine (2020)

Mis-configured AWS WAF → 106M records exfiltrated by a former AWS engineer

Penalty
$80M + $190M class
Regulator
OCC + class action
Jurisdiction
United States
Records affected
106M

What happened

A former AWS engineer exploited a misconfigured Web Application Firewall (Server-Side Request Forgery vector) to reach an internal metadata service and exfiltrate 106M credit-card applications. The OCC fined Capital One $80M citing insufficient cloud risk assessment + inadequate corrective action. A class action later settled for ~$190M.

Root cause

What every team should do

  1. Disable IMDSv1 / enforce IMDSv2 on all EC2 instances
  2. Apply least-privilege to IAM instance roles; scope S3 access by prefix
  3. Egress monitoring: alert on data flowing to unknown destinations
  4. Run a cloud-specific risk assessment when migrating regulated workloads
Source: OCC consent order (Aug 6, 2020).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which GLBA controls you are missing — mapped to enforcement patterns like this one.

Run my GLBA audit Generate missing policies

Related enforcement actions

Equifax
$700M+
Largest consumer-data settlement in US history — Apache Struts patch ignored for 76 days
Block / Cash App
$175M
Failed fraud investigations + inadequate Reg E dispute handling