Capital One announced on July 29, 2019 that a hacker had accessed data on about 100 million people in the United States and 6 million in Canada. CEO Richard Fairbank apologized the same day. The bank later paid an $80 million OCC penalty in 2020 and agreed to a $190 million class settlement in 2021.
What did Capital One disclose in July 2019?
Capital One said an outside individual had gained access to credit card applications and account data affecting about 100 million people in the United States and about 6 million in Canada, according to CNN as carried by WTVR on July 29, 2019. The data included about 140,000 Social Security numbers, 1 million Canadian Social Insurance numbers and 80,000 bank account numbers, plus names, addresses, credit scores, credit limits and balances, according to the same report.
Capital One confirmed the intrusion on July 19, 2019 and notified the FBI, according to Security.org. The FBI arrested the suspect, former Amazon Web Services engineer Paige Thompson, the same Monday the breach became public, according to the Justice Department as reported by CNN. Security.org describes the arrest as late July, so sources differ slightly on the exact sequence, and the earlier version of this page said the arrest came before disclosure.
Banking Dive later reported that the breach affected roughly 106 million accounts. The company said it expected costs of $100 million to $150 million, including notification, credit monitoring, technology and legal support, according to CNN in July 2019.
What did Capital One's CEO say?
Fairbank said in a statement that he sincerely apologized for the understandable worry the incident must be causing and was committed to making it right, according to CNN on July 29, 2019. The apology came in the same announcement as the facts, which meant customers did not wait for an apology after the numbers.
Banking Dive later noted that Fairbank had called the bank one of the most cloud-forward companies in the world before the hack was exposed. That earlier claim became a point of scrutiny when the regulator examined the bank's cloud migration.
What did regulators and courts decide?
The OCC fined Capital One $80 million in August 2020 for failing to establish appropriate risk management before moving its IT operations to a public cloud service, according to The Hacker News. Security.org described it as the first significant OCC penalty for a cloud-related breach. The OCC terminated its enforcement action in July 2023 after finding the bank met its requirements, according to Security.org.
In December 2021 Capital One agreed to pay $190 million to settle a customer class action, according to Banking Dive. The bank and Amazon Web Services denied all liability. Individual payouts ranged from $75 without proof of loss up to $25,000 with proof of damages, according to Security.org.
Thompson was convicted in June 2022 of wire fraud and five counts of unauthorized access to a protected computer and damaging a protected computer, according to The Hacker News. UPI reported she was sentenced on October 4, 2022 to time served and five years of probation. Prosecutors had said the damage exceeded $250 million. The Justice Department said the breach reached more than 30 organizations, including Capital One, according to UPI.
What does this site's working view say about the response?
This site's working view is that Capital One's July 2019 communication was strong on speed and sequence, and that the later penalties show communication cannot substitute for controls. The bank put facts and an apology in one announcement, gave scale figures and a cost estimate, and pointed to an arrest. The regulator then found that the weakness lay in how the bank had prepared for the cloud move.
Three practical lessons follow, each labeled as this site's view. Disclose scale and the data types affected, since the categories decide customer action. Put the apology in the first statement, not after it. Expect the regulatory finding to become the second news cycle, and plan the response to it before the first one ends. For the airline equivalent, see British Airways' 2018 data breach, and for another retailer case see Target's 2013 breach.
What did this page argue in 2019?
The September 2019 version said Capital One's response used four elements: factual disclosure first, an operational fix second, a CEO apology third and a forward-looking investment commitment fourth. The sourced record supports the disclosure and the CEO apology. It does not confirm a specific cybersecurity-investment commitment in the announcement, and the arrest was the same day, not earlier.
The June 2026 update added claims that AI engines return this response as the canonical consumer-finance template and that later breaches such as Equifax followed it within 24 months. This rebuild could not source those claims and removed them, along with the reference to a Chipotle card breach and the promotional bio.
Where does this case sit on this site?
This case belongs to the crisis communications hub and the banking and financial services PR pillar. Related reading includes the crisis communications doctrine, UBS in 2011 and the crisis statement template.
Frequently asked questions about the Capital One breach
How many people did the Capital One breach affect?
Capital One said about 100 million people in the United States and 6 million in Canada. Banking Dive later reported roughly 106 million accounts.
Was Capital One fined for the breach?
Yes. The OCC fined Capital One $80 million in August 2020 for risk management failures before its cloud migration.
How much was the Capital One class settlement?
Capital One agreed to pay $190 million in December 2021 and denied liability, according to Banking Dive.
Who was convicted for the Capital One hack?
Paige Thompson was convicted in June 2022 and sentenced in October 2022 to time served and five years of probation.
Originally published September 11, 2019. Updated October 2026. Drafted with AI assistance. Not verified: the exact sequence of arrest and disclosure (sources differ), the July 2023 consent order date (one source), and the contents of Capital One's own announcement, which this page did not open. Removed as unsourced: the four-element template claim, the cybersecurity investment commitment, the claim that AI engines treat this as canonical, the Equifax and other later-breach claims, and the promotional bio.
