Data breaches have become a defining risk of modern digital life. The Capital One breach is one of the most significant in recent memory — and if you've ever had an account with the affected service, your personal data may be circulating among cybercriminals right now.

This guide explains exactly what happened, what data was taken, and how you can check whether your information was exposed — for free, in 30 seconds.

What Happened?

The details of this breach are covered in the FAQ section below, where we answer the most important questions clearly and concisely. The key facts: who was affected, what data was taken, how attackers got in, and what the consequences have been.

Why Does This Still Matter?

Many people assume that because a breach happened years ago, the risk has passed. In reality, stolen data is sold, traded, and reused for years after a breach. Credentials from old breaches are used in credential stuffing attacks — automated attempts to log in to your other accounts using the same email and password combination.

If you reused the same password across multiple sites, one old breach can unlock dozens of your current accounts.

How to Check If You Were Affected

The fastest way is to use our free breach checker. Enter your email address and we'll scan it against known breach databases instantly — no signup required.

If your email appears in a breach, you'll see exactly which breaches affected it and what type of data was exposed. That tells you precisely where to start.

What to Do If You Were Affected

If your data was in this breach — or any breach — take these steps:

Frequently Asked Questions

When did the Capital One data breach happen?

The breach occurred between 22 and 23 March 2019. Capital One discovered it in July 2019 following a tip-off, and disclosed it publicly on 29 July 2019.

How did the Capital One breach happen?

A former Amazon Web Services engineer exploited a misconfigured web application firewall (WAF) to perform a Server Side Request Forgery (SSRF) attack, gaining access to Capital One's AWS S3 storage buckets containing customer data.

What data was stolen in the Capital One breach?

Approximately 100 million US customers and 6 million Canadian customers were affected. Stolen data included names, addresses, phone numbers, email addresses, dates of birth, credit scores, credit limits, balances, and Social Security numbers (for approximately 140,000 customers) and bank account numbers (for approximately 80,000 customers).

How do I check if I was affected by the Capital One breach?

Capital One notified affected customers directly. Enter your email in the free checker at Scan My Shadow, and check your Capital One account for any notification banner or email from the company.

What was the outcome of the Capital One breach?

Capital One paid an $80 million fine to the OCC. The attacker was arrested within days of disclosure and later convicted on federal charges. Capital One also established a $190 million class-action settlement fund for affected customers.

Sources

Related Reading