Capital One A.I CyberSecurity Scoring
Capital One
Company Information
Website:http://www.capitalone.com
Employees number:81,873
Number of followers:1,054,217
NAICS:52
Industry Type:Financial Services
Homepage:capitalone.com
Capital One Risk Score (AI oriented)
Between 600 and 649
Capital OneFinancial Services
Updated:
01/04/2026
01/04/2026
638/1000
Poor
Caa
Capital One Global Score (TPRM)
xxxx
Capital OneFinancial Services
Score locked

Capital OnePoor
Current Score
638Caa (POOR)
01000
11 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
655
MAY 2026
647
APRIL 2026
647
MARCH 2026
637
FEBRUARY 2026
635
JANUARY 2026
632
DECEMBER 2025
628
NOVEMBER 2025
624
OCTOBER 2025
620
SEPTEMBER 2025
616
AUGUST 2025
612
JULY 2025
608
MAY 2025
675
Breach
30 May 2025 • Capital One
Capital One
Capital One Firewall Misconfiguration (2025)
599
CRITICAL-76
CAP721053025
In 2025, Capital One experienced a significant data breach due to a misconfigured web application firewall (WAF). Attackers exploited this vulnerability to steal AWS credentials and access 100 million customer records. The breach highlighted critical gaps in regular WAF rule audits, enforcement of multi-factor authentication for privileged accounts, and real-time API activity monitoring. Post-incident, Capital One implemented Lacework's AI-driven anomaly detection, reducing false positives by 70% and halving response times.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2023
606
Breach
01 Feb 2023 • Capital One
Capital One Services, LLC
Capital One Data Breach
567
CRITICAL-39
CAP720072825
The Washington State Office of the Attorney General reported a data breach involving Capital One on May 26, 2023. The breach occurred on February 1, 2023, affecting 605 Washington residents and potentially compromising their names, Social Security Numbers, and financial information.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2022
617
Breach
01 Aug 2022 • Capital One
Capital One
Capital One Data Breach
579
CRITICAL-38
CAP326072625
The Maine Office of the Attorney General reported a data breach involving Capital One on June 16, 2023. The breach occurred between August 11, 2022, and May 22, 2023, due to insider wrongdoing, impacting one Maine resident and affecting a total of 82 individuals. Personal information compromised included names, credit card numbers, Social Security numbers, and other financial details, and 24 months of free credit monitoring was offered to the affected individual.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2020
553
Breach
10 Nov 2020 • Capital One
Capital One, National Association
Capital One Data Breach
514
MEDIUM-39
CAP538072725
On March 22, 2021, the Maine Attorney General's Office reported a data breach involving Capital One, National Association, which occurred on November 10, 2020. The breach potentially exposed financial account numbers and affected a total of 426 individuals, including 2 residents of Maine. Although there is no evidence of data being breached, customers are at risk of future fraud, prompting notification and the offering of identity theft protection services.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2020
579
Breach
01 Sep 2020 • Capital One
Capital One
Capital One Insider Wrongdoing Breach (2021)
541
HIGH-38
CAP019090625
In April 2021, the Maine Office of the Attorney General disclosed an insider wrongdoing breach at Capital One, occurring between September 2, 2020, and February 25, 2021. The incident involved an internal actor who improperly accessed and potentially compromised sensitive personal information of at least one Maine resident, including credit card account numbers and Social Security numbers. Such data exposure poses significant risks, including identity theft, financial fraud, and long-term reputational harm to the affected individual. In response, Capital One provided 24 months of free credit monitoring via TransUnion’s myTrueIdentity service to mitigate potential damages. The breach highlights vulnerabilities in internal controls, emphasizing the critical need for robust insider threat detection and access governance to prevent unauthorized data handling by employees or contractors.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2020
599
Breach
01 May 2020 • Capital One
Capital One, National Association
Capital One Data Breach
559
HIGH-40
CAP832072925
The Maine Office of the Attorney General reported that Capital One experienced a data breach involving unauthorized access by a former employee from May 15, 2020, to June 2, 2020. A total of 1,277 individuals were affected, including eight Maine residents whose personal information such as names, addresses, Social Security numbers, and account numbers may have been accessed. Capital One has provided these residents with written notification and offered two years of free credit monitoring through TransUnion.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2019
642
Breach
01 Jul 2019 • Capital One
Capital One
Capital One Data Breach
550
CRITICAL-92
CAP163030323
Capital One, the Virginia-based bank with a popular credit card business, announced that a hacker had accessed about 100 million credit card applications.
It was also found that thousands of Social Security and bank account numbers were also taken.
The FBI has arrested a Seattle-area woman, Paige A. Thompson, on a charge of computer fraud and abuse, according to court records.
The hack was expected to cost the company between $100 million and $150 million in the near term.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2019
739
Breach
16 Jun 2019 • Capital One
Capital One
Capital One Data Breach and Class Action Settlement (2019-2025)
640
CRITICAL-99
CAP5092250102525
In 2019, Capital One suffered a massive data breach exposing the sensitive personal and financial information of 100 million customers, including Social Security numbers (SSNs), bank account details, credit scores, and transaction data. The breach stemmed from a misconfigured firewall in the bank’s cloud infrastructure, exploited by a hacker who gained unauthorized access. Beyond the immediate data exposure, the incident eroded public trust, triggered regulatory scrutiny, and led to a $425 million class-action settlement—one of the largest in U.S. banking history. The settlement addressed both the breach and allegations of deceptive marketing tied to the bank’s 360 Savings accounts, where customers claimed they received lower interest rates than advertised. The fallout included financial restitution ($300M in cash payments, $125M in interest adjustments), reputational damage, and heightened compliance demands. The breach underscored systemic vulnerabilities in financial institutions’ cybersecurity practices, particularly in securing cloud-based customer data.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2019
780
Breach
22 Mar 2019 • Capital One
Capital One
Capital One Data Breach
734
CRITICAL-46
CAP830072525
The California Office of the Attorney General reported a data breach by Capital One involving unauthorized access to personal information on August 12, 2019. The breach occurred on March 22 and 23, 2019, affecting approximately 140,000 Social Security numbers and 80,000 linked bank account numbers, along with various personal details of individuals who applied for or were customers of Capital One's credit card products.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2017
788
Breach
06 Feb 2017 • Capital One
Capital One
Capital One Data Breach
750
CRITICAL-38
CAP502072625
The California Attorney General reported a data breach involving Capital One on February 6, 2017. The breach involved unauthorized access to customer accounts using stolen usernames and passwords, potentially affecting personal information such as names, addresses, and account numbers. Specific details about the number of individuals affected and the exact date of the breach are unknown.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2017
827
Breach
27 Jan 2017 • Capital One
Capital One Services, LLC
Capital One Data Breach
788
CRITICAL-39
CAP641080525
The California Office of the Attorney General reported a data breach involving Capital One Services, LLC on August 9, 2018. The breach occurred between January 27, 2017, and April 20, 2017, potentially affecting personal information of 586 California residents, including names, addresses, account numbers, telephone numbers, transaction history, dates of birth, and Social Security numbers.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Capital One ??
What was Capital One's A.I Rankiteo Cyber Score in May 2026 ??
What was Capital One's A.I Rankiteo Cyber Score in April 2026 ??
What was Capital One's A.I Rankiteo Cyber Score in March 2026 ??
What was Capital One's A.I Rankiteo Cyber Score in February 2026 ??
What was Capital One's A.I Rankiteo Cyber Score in January 2026 ??
What was Capital One's A.I Rankiteo Cyber Score in December 2025 ??
What was Capital One's A.I Rankiteo Cyber Score in November 2025 ??
What was Capital One's A.I Rankiteo Cyber Score in October 2025 ??
What was Capital One's A.I Rankiteo Cyber Score in September 2025 ??
What was Capital One's A.I Rankiteo Cyber Score in August 2025 ??
What was Capital One's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Capital One's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Capital One ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Capital One's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?