Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Capital One

Capital One Vendor Cyber Rating & Cyber Score

capitalone.com

At Capital One, we're making things better for our customers and associates through innovation and collaboration. We were founded on the belief that everyone deserves financial freedom—and are dedicated to a world where all have equal opportunity to prosper. Banking is in our DNA, but we are so much more than a bank. We always think about what’s next—and how we can bring our customers the tools needed to improve their financial lives. Your ideas, experiences and skills will help make banking better. You’ll be part of a supportive culture while earning amazing benefits. That’s life at Capital One. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable


Capital One A.I CyberSecurity Scoring

Capital One
Company Information
Website:http://www.capitalone.com
Employees number:81,873
Number of followers:1,054,217
NAICS:52
Industry Type:Financial Services
Homepage:capitalone.com
Capital One Risk Score (AI oriented)
Between 600 and 649
logo
Capital OneFinancial Services
Updated:
01/04/2026
638/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Capital One Global Score (TPRM)
xxxx
logo
Capital OneFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Capital One
Capital OnePoor
Current Score
638Caa (POOR)
01000
11 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
655Before Incident
MAY 2026
647Before Incident
APRIL 2026
647Before Incident
MARCH 2026
637Before Incident
FEBRUARY 2026
635Before Incident
JANUARY 2026
632Before Incident
DECEMBER 2025
628Before Incident
NOVEMBER 2025
624Before Incident
OCTOBER 2025
620Before Incident
SEPTEMBER 2025
616Before Incident
AUGUST 2025
612Before Incident
JULY 2025
608Before Incident
MAY 2025
675Before Incident
Breach
30 May 2025Capital One
Capital One

Capital One Firewall Misconfiguration (2025)

599After Incident
CRITICAL-76
CAP721053025
In 2025, Capital One experienced a significant data breach due to a misconfigured web application firewall (WAF). Attackers exploited this vulnerability to steal AWS credentials and access 100 million customer records. The breach highlighted critical gaps in regular WAF rule audits, enforcement of multi-factor authentication for privileged accounts, and real-time API activity monitoring. Post-incident, Capital One implemented Lacework's AI-driven anomaly detection, reducing false positives by 70% and halving response times.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Theft
IMPACT
Financial Loss: $4.35 millionData Compromised: 100 million recordsBrand Reputation Impact: Reputational damageLegal Liabilities: Regulatory penalties under GDPR and HIPAA
DATA BREACH
Type Of Data Compromised: Customer RecordsNumber Of Records Exposed: 100 million
FEBRUARY 2023
606Before Incident
Breach
01 Feb 2023Capital One
Capital One Services, LLC

Capital One Data Breach

567After Incident
CRITICAL-39
CAP720072825
The Washington State Office of the Attorney General reported a data breach involving Capital One on May 26, 2023. The breach occurred on February 1, 2023, affecting 605 Washington residents and potentially compromising their names, Social Security Numbers, and financial information.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesSocial Security Numbersfinancial information
DATA BREACH
namesSocial Security Numbersfinancial informationSensitivity Of Data: High
AUGUST 2022
617Before Incident
Breach
01 Aug 2022Capital One
Capital One

Capital One Data Breach

579After Incident
CRITICAL-38
CAP326072625
The Maine Office of the Attorney General reported a data breach involving Capital One on June 16, 2023. The breach occurred between August 11, 2022, and May 22, 2023, due to insider wrongdoing, impacting one Maine resident and affecting a total of 82 individuals. Personal information compromised included names, credit card numbers, Social Security numbers, and other financial details, and 24 months of free credit monitoring was offered to the affected individual.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namescredit card numbersSocial Security numbersother financial details
DATA BREACH
namescredit card numbersSocial Security numbersother financial detailsSensitivity Of Data: High
NOVEMBER 2020
553Before Incident
Breach
10 Nov 2020Capital One
Capital One, National Association

Capital One Data Breach

514After Incident
MEDIUM-39
CAP538072725
On March 22, 2021, the Maine Attorney General's Office reported a data breach involving Capital One, National Association, which occurred on November 10, 2020. The breach potentially exposed financial account numbers and affected a total of 426 individuals, including 2 residents of Maine. Although there is no evidence of data being breached, customers are at risk of future fraud, prompting notification and the offering of identity theft protection services.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
financial account numbersIdentity Theft Risk: High
DATA BREACH
financial account numbersSensitivity Of Data: High
SEPTEMBER 2020
579Before Incident
Breach
01 Sep 2020Capital One
Capital One

Capital One Insider Wrongdoing Breach (2021)

541After Incident
HIGH-38
CAP019090625
In April 2021, the Maine Office of the Attorney General disclosed an insider wrongdoing breach at Capital One, occurring between September 2, 2020, and February 25, 2021. The incident involved an internal actor who improperly accessed and potentially compromised sensitive personal information of at least one Maine resident, including credit card account numbers and Social Security numbers. Such data exposure poses significant risks, including identity theft, financial fraud, and long-term reputational harm to the affected individual. In response, Capital One provided 24 months of free credit monitoring via TransUnion’s myTrueIdentity service to mitigate potential damages. The breach highlights vulnerabilities in internal controls, emphasizing the critical need for robust insider threat detection and access governance to prevent unauthorized data handling by employees or contractors.
INCIDENT DETAILS -
TYPE
Insider Threat / Data Breach
IMPACT
Brand Reputation Impact: Potential (limited to one individual)
DATA BREACH
Credit Card Account NumbersSocial Security Numbers (SSN)Sensitivity Of Data: High (PII, Financial Data)
MAY 2020
599Before Incident
Breach
01 May 2020Capital One
Capital One, National Association

Capital One Data Breach

559After Incident
HIGH-40
CAP832072925
The Maine Office of the Attorney General reported that Capital One experienced a data breach involving unauthorized access by a former employee from May 15, 2020, to June 2, 2020. A total of 1,277 individuals were affected, including eight Maine residents whose personal information such as names, addresses, Social Security numbers, and account numbers may have been accessed. Capital One has provided these residents with written notification and offered two years of free credit monitoring through TransUnion.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesAddressesSocial Security numbersAccount numbers
DATA BREACH
NamesAddressesSocial Security numbersAccount numbersSensitivity Of Data: High
JULY 2019
642Before Incident
Breach
01 Jul 2019Capital One
Capital One

Capital One Data Breach

550After Incident
CRITICAL-92
CAP163030323
Capital One, the Virginia-based bank with a popular credit card business, announced that a hacker had accessed about 100 million credit card applications. It was also found that thousands of Social Security and bank account numbers were also taken. The FBI has arrested a Seattle-area woman, Paige A. Thompson, on a charge of computer fraud and abuse, according to court records. The hack was expected to cost the company between $100 million and $150 million in the near term.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
$100 million$150 millioncredit card applicationsSocial Security numbersbank account numbers
DATA BREACH
credit card applicationsSocial Security numbersbank account numbersNumber Of Records Exposed: 100 million
JUNE 2019
739Before Incident
Breach
16 Jun 2019Capital One
Capital One

Capital One Data Breach and Class Action Settlement (2019-2025)

640After Incident
CRITICAL-99
CAP5092250102525
In 2019, Capital One suffered a massive data breach exposing the sensitive personal and financial information of 100 million customers, including Social Security numbers (SSNs), bank account details, credit scores, and transaction data. The breach stemmed from a misconfigured firewall in the bank’s cloud infrastructure, exploited by a hacker who gained unauthorized access. Beyond the immediate data exposure, the incident eroded public trust, triggered regulatory scrutiny, and led to a $425 million class-action settlement—one of the largest in U.S. banking history. The settlement addressed both the breach and allegations of deceptive marketing tied to the bank’s 360 Savings accounts, where customers claimed they received lower interest rates than advertised. The fallout included financial restitution ($300M in cash payments, $125M in interest adjustments), reputational damage, and heightened compliance demands. The breach underscored systemic vulnerabilities in financial institutions’ cybersecurity practices, particularly in securing cloud-based customer data.
INCIDENT DETAILS -
TYPE
Data BreachClass Action LawsuitRegulatory Non-Compliance
MOTIVATION
Financial TheftFraudExploitation of Misconfigured Systems
IMPACT
Financial Loss: $425M (settlement amount)Social Security Numbers (SSNs)Credit ScoresTransaction DataBank Account NumbersPersonal Identifiable Information (PII)Credit Card Application Data (2005-2019)AWS Cloud InfrastructureCapital One Credit Card Application SystemCustomer Savings Accounts (360 Savings)Operational Impact: Significant reputational damage; regulatory scrutiny; customer trust erosion; legal and compliance costsCustomer Complaints: Widespread complaints regarding misleading marketing practices for 360 savings accounts (lower-than-advertised interest rates)Brand Reputation Impact: Severe damage due to breach and subsequent allegations of unfair practices; loss of customer trust$425M class action settlementPotential regulatory fines (e.g., CFPB, OCC)Ongoing litigation from state attorneys general (e.g., New York)Identity Theft Risk: High (due to exposure of SSNs and PII)Payment Information Risk: High (bank account numbers and credit card data exposed)
DATA BREACH
Personally Identifiable Information (PII)Financial DataCredit HistoryTransaction RecordsNumber Of Records Exposed: 100,000,000+ (U.S. and Canada)Sensitivity Of Data: High (SSNs, bank account details, credit scores)Data Exfiltration: Yes (data stolen and partially leaked online)Data Encryption: No (data stored in unencrypted S3 buckets)PDFsCSV filesDatabase dumpsPersonally Identifiable Information: Yes (names, addresses, SSNs, dates of birth)
MARCH 2019
780Before Incident
Breach
22 Mar 2019Capital One
Capital One

Capital One Data Breach

734After Incident
CRITICAL-46
CAP830072525
The California Office of the Attorney General reported a data breach by Capital One involving unauthorized access to personal information on August 12, 2019. The breach occurred on March 22 and 23, 2019, affecting approximately 140,000 Social Security numbers and 80,000 linked bank account numbers, along with various personal details of individuals who applied for or were customers of Capital One's credit card products.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Social Security numbersBank account numbersPersonal details
DATA BREACH
Social Security numbersBank account numbersPersonal details140,000 Social Security numbers80,000 bank account numbersSensitivity Of Data: High
FEBRUARY 2017
788Before Incident
Breach
06 Feb 2017Capital One
Capital One

Capital One Data Breach

750After Incident
CRITICAL-38
CAP502072625
The California Attorney General reported a data breach involving Capital One on February 6, 2017. The breach involved unauthorized access to customer accounts using stolen usernames and passwords, potentially affecting personal information such as names, addresses, and account numbers. Specific details about the number of individuals affected and the exact date of the breach are unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesAddressesAccount Numbers
DATA BREACH
Personal InformationNamesAddressesAccount Numbers
JANUARY 2017
827Before Incident
Breach
27 Jan 2017Capital One
Capital One Services, LLC

Capital One Data Breach

788After Incident
CRITICAL-39
CAP641080525
The California Office of the Attorney General reported a data breach involving Capital One Services, LLC on August 9, 2018. The breach occurred between January 27, 2017, and April 20, 2017, potentially affecting personal information of 586 California residents, including names, addresses, account numbers, telephone numbers, transaction history, dates of birth, and Social Security numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesaddressesaccount numberstelephone numberstransaction historydates of birthSocial Security numbers
DATA BREACH
namesaddressesaccount numberstelephone numberstransaction historydates of birthSocial Security numbersSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Capital One ?
?
What was Capital One's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Capital One's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Capital One's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Capital One's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Capital One's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Capital One's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Capital One's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Capital One's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Capital One's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Capital One's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Capital One's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Capital One's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Capital One ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Capital One's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?