Yathartha Shrestha'
Yathartha Shrestha'
23050342 YatharthaShrestha'.docx
Islington College,Nepal
Document Details
Submission ID
trn:oid:::3618:89656388 10 Pages
Download Date
File Name
23050342 YatharthaShrestha'.docx
File Size
14.2 KB
9% Overall Similarity
The combined total of all matches, including overlapping sources, for each database.
0 Missing Citation 0%
Matches that have quotation marks, but no in-text citation
Integrity Flags
0 Integrity Flags for Review
Our system's algorithms look deeply at a document for any inconsistencies that
would set it apart from a normal submission. If we notice something strange, we flag
it for you to review.
0 Missing Citation 0%
Matches that have quotation marks, but no in-text citation
Top Sources
The sources with the highest number of matches within the submission. Overlapping sources will not be displayed.
1 Submitted works
2 Submitted works
3 Submitted works
4 Submitted works
5 Submitted works
6 Submitted works
7 Internet
khazna.ku.ac.ae <1%
8 Internet
www.trackr.live <1%
9 Submitted works
10 Internet
money.cnn.com <1%
11 Submitted works
12 Submitted works
1. Introduction
In the past decade there has been exponential growth in the instance of data
information private data over the internet. This increase in the exposure can be largely
2 credited to two factors either the increasing connectivity of on premises data centres
infrastructure like AWS, Google Cloud, Dropbox and many more. (Shaharyar Khan,
been increasing in the number vulnerabilities that exists in the system, leading to high
risk of cyber based attacks and data breaches. The common types of cyberattacks are
as follows:
Whale-phishing attack
Ransomware attack
Session hijacking
The Capital one financial corporation is one of the major American banks holding
company which was founded on 21st July 1994 which deals with loans, credit cards,
McLean, Virginia. Capital one is the ninth largest banked in United States based on the
5 assets they managed as of (Us gov, 2025). Capital one is the third largest issuer of
MasterCard and visa credit cards in the USA and the largest car finance companies.
As of 31st December 2022, the company has over $144 billion of credit card loan
receivables, $75 billion form loans and over $85 billion from commercial loans ( U.S.
On 29th July 2019, the capital one suffered from one of the largest cybersecurity
incidents in the history of banking. This data breach involved unauthorized access to
9 the personal and financial information of over 100 million citizens of United States of
America and over 6 million citizens of Canada. Approximately One hundred forty
12 thousand social security number of U.S credit card customer and about 80,000 bank
3 account number which were linked were exposed publicly (Information on the Capital
3 One cyber incident, 2022). Over 1 million Social Insurance Numbers of Canadians
2 were exposed in this incident. This attack was executed by the formal employee of
Amazon Web Services Paige Thompson. The attack did not include any advance
11 Paige Thompson targeted a misconfigured web application firewall (WAF) that enabled
her to control Capital One server to make unauthorized request to the AWS server.
Through this attack she got access AWS metadata service which allowed her to get
6 Management (IAM) role. Using these credentials, she got access to Capital one’s
6 Amazon s3 storage bucket where sensitive customer data were stored. (Villa, N.d).
The Data breach exposed a major security flaw in cloud financial infrastructure drawing
attention to the danger of misconfiguration and overly permissive access controls. The
capital one first found out about data breach in July 2019 when they received tip that
stolen data had been posted on GitHub. Before company could respond millions of
10 sensitive personal and financial data had already been accessed, including Social
Security numbers, credit card applications, and bank account details (N.d, 2019).
After the discovery of the breach, capital one instantly reacted to limit the extent of the
issue and prevent additional damage. The company work alongside law enforcement
and cybersecurity professional to investigate the issue and identify the vulnerability
which they took advantage of. The company also informed affected customer and
1 provided them with free credit monitoring and identity protection services. To address
the issue, the company implemented tighter security practices, including more
To prevent such occurrences in the future, Capital One implemented several steps.
access controls, and other security configurations closely. Second, Capital One
security information and event management (SIEM) solutions and intrusion detection
2. Social Issues
The capital once data breach raised many social concerns related to cyber security
privacy and public trust in banking institutions. The compromise of personal data
including banking information and social security numbers left mullions of customer
vulnerable to the threats of financial fraud and identity theft (Stone, 2020). The victims
of this cyber-attack had to take major security measures such as fraud alerts and credit
card monitoring which furthermore increased the financial weightage to the individual.
Below there are five social issues that came up after the capital one incident
The data breach heavily impacted the confidence of the people particularly of lower-
income households who heavily relay on banking services to protect their private data.
More than 100 million people were affected in this scandal, among them many people
began to question the reliability of online banking services. After the incident the
survey that was conducted which showed that over 60% of customers reported a loss
After capital one incident banking details, social security number and personal
information of millions of people were released openly on the internet which heavily
increase the risk of identity theft of millions of people. Victims were forced to bare
costly preventative methods such as signing up for credit card monitoring services and
many more (Stone, 2020). As the reliance of people on digital means increases the
risk of identity theft increases along in 2023 nearly 4.3million American an people were
victims of identity theft in first nine months with the total lost staking over 6 billion
The incident burst public debate over the ethics of cloud components and data
storage. Capital one decision to store sensitive private information of public customers
on a third-party infrastructure like Amazon AWS with insuring highest level of security
raised concerns over the responsibility of corporate organization (Noonan, N.D). The
tainting users' confidence in cloud service providers. To counter such issues the
corporate authorities must notice a clear define policies and regulatory system to
The capital one incident highlighted the gaps that existed in the digital protection
about the lack of effective regulation and insisted new cybersecurity rules and
regulations that reflect the dynamic threat environment. The breach Emphasized the
need for stronger legal guidelines and corporate management protocols to prevent
The capital one data breach affected insecure population, particularly lower income
people who are to use digital banking services as a means to access basic banking
and financial services. Unlike customer with high wealth these group of individual lack
resources or financial literacy that are necessary to reduce the effect of such large-
scale data breach. They were therefore made even more prone to financial exploitation
3. Ethical Issue
The capital one data breach raises major ethical concerns, especially around
company’s responsibility and how it uses to handle and protect sensitive data of the
consumers. First of all, the initial fear was that Capital One, despite being known as
the first one to adopt cloud computing technology in banking sector, was unable to
provide necessary security to data security (Capital One, 2022). These situations raise
the expense of the protection of the company's customers' information. Below are the
five major ethical concerns raised by the capital one data breach:
The failure of capital one corporation to implement enough control to counter incoming
security threads such as misconfigured firewall and too much permissive access
control. By ignoring proper secure its cloud infrastructure capital, one reviled the
responsibility that a big corporate organization must secure its customer data and
Cloud computing is one of the revolutionary forces, yet its ethical responsibility must
not be overlooked. The increase in the adoption of cloud infrastructure has presented
serious ethical challenges, majorly around data privacy and security. As from the
capital one incident outsourcing the storage of sensitive data in the likes of cloud-
based infrastructure like AWS with out implementing highest level of security measures
is an ethical issue in terms of risk accountability. This incident calls attention to the
data particularly with third party cloud storage services (Popat, 2025).
Another major ethical concern is the lack of transparency between corporation and the
customers during the breach. Capital One got to know about the incident only when
the third party notified them with in which the sensitive information of capital one
3 customer have already been released in the public premises (Information on the
Capital One cyber incident, 2022). In today world transparency beings trust and loyalty,
hiding important information to the customer destroyed their trust and signed a
The moment a big corporate organization gains access to sensitive personal data it
takes on not only a technical responsibility but also ethical responsibility to safeguard
the data. In capital one’s case the disclosure of the data breach was not only delayed
but was discovered by a third-party media which took questions about the capital one’s
accountability toward public trust. In this digital era where trust is limited, and
2 The capital one data breach was caused due to the misconfigured firewall in the
company cloud system which was a small mistake which could be easily avoided but
due to the lack of frequent security check protocols sensitive information of millions of
people were compromised. Had Capital One frequently conducted security checks of
its systems, the misconfiguration would have been easily discovered and fixed before
the data breach happened. Ethical risk analysis is necessary in today's high-risk digital
environment to prevent harm, ensure accountability, and maintain public trust (Klein,
2024).
There are many ethical issues that arise from capital one data breach including
the data breach to public. The disparity low-income consumer getting less protection to
threads compare to wealthier clients. These issues highlight the need for stronger data
security regulations and fair treatment for all customers which highlights the
importance for analysing this matter from multiple ethical perspective. From Utilitarian
N.d) the capital one incident impacted all the customer, employees and stakeholder
theory that uses rules to distinguish what is right from wrong (ethicsunwrapped, N.d),
highlights capital one moral responsibility to protect sensitive data of its consumers
and be open about the data breach, which raised the question if the company fulfilled
Additionally applying social justice theory which highlights the power dynamics
between and among different groups (Garcia, 2023) highlights the power inequality in
protection for low-income clients compare to high income clients which raised concern
4 about the equality in data security practices. Lastly the Corporate social responsibility
accountable to itself, public and stake holder. (Fernando, 2024) shows the capital
one’s responsibility to ethical standards its role in society, forcing the company to take
preventive steps in preserving customers data. By analysing the data breach through
this ethical perspective, it became clear that stronger data security practices, greater
transparency, and equitable treatment for all consumers are necessary for building