AWSIncident TeardownsRetrospectives

Capital One (July 2019): SSRF, the EC2 Metadata Service and 100 Million Records

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2019, written in 2026 with the benefit of hindsight.

On July 29, 2019, Capital One disclosed a breach affecting about 100 million people in the US and 6 million in Canada. It became the defining cloud breach of the decade — and a case study in how a single misconfiguration can combine with excessive permissions.

How it happened

A former AWS employee exploited a misconfigured web application firewall running on an EC2 instance in Capital One's AWS environment. The WAF was vulnerable to server-side request forgery (SSRF): it could be tricked into making requests on the attacker's behalf.

The attacker used that to query the EC2 instance metadata service (IMDS), which returned temporary credentials for the IAM role attached to the instance. That role had permission to list and read a large number of S3 buckets. With those credentials, the attacker downloaded data including credit card applications, Social Security numbers and bank account numbers.

The response and consequences

Capital One learned of the breach through a tip to its responsible disclosure program after the attacker discussed it online. The US Office of the Comptroller of the Currency fined Capital One $80 million in 2020, citing risk management failures in its cloud migration. The attacker was convicted in 2022.

What AWS changed

In November 2019, AWS released IMDSv2, which requires a session token obtained with a PUT request — blocking most SSRF attacks against the metadata service.

Lessons in hindsight

  • Least privilege on instance roles. The WAF role never needed access to so much data.
  • Enforce IMDSv2 on every instance.
  • Defense in depth: one flaw should not lead straight to sensitive data.
  • Monitor unusual data access by roles.

Capital One was a sophisticated cloud adopter — which is why the breach resonated. Security in the cloud depends on configuration and permissions, not just on the provider.

capital one breachCapital One2019

More on this story