English | Español
April 22, 2022 update:
2019 Cyber Incident Settlement Reached. On February 7, 2022, a U.S. federal court preliminarily approved a class action settlement relating to the cyber incident Capital One announced in July 2019. Please visit www.CapitalOneSettlement.com for additional details.
February 22, 2021 update:
On January 27, 2021, as a result of Capital One’s ongoing analysis of the files stolen by the unauthorized individual in the 2019 Cybersecurity Incident, we discovered approximately 4,700 U.S. credit card customers or applicants whose Social Security Numbers were among the data accessed, but not previously known. Capital One is directly notifying these affected individuals and will make two years of free credit monitoring and identity protection available at no cost to them.
On July 19, 2019, we determined that an outside individual gained unauthorized access and obtained certain types of personal information about Capital One credit card customers and individuals who had applied for our credit card products.
We immediately fixed the issue and promptly began working with federal law enforcement. The outside individual who took the data was captured by the FBI. The government has stated they believe the data has been recovered and that there is no evidence the data was used for fraud or shared by this individual.
Safeguarding information is essential to our mission and our role as a financial institution. We have invested heavily in cybersecurity and will continue to do so. We have incorporated the learnings from this incident to further strengthen our cyber defenses.
Richard D. Fairbank, Chairman and CEO
"While I am grateful that the perpetrator has been caught, I am deeply sorry for what has happened...I sincerely apologize for the understandable worry this incident must be causing those affected and I am committed to making it right."
Based on our analysis, this event affected approximately 100 million individuals in the United States and approximately 6 million in Canada.
Importantly, no credit card account numbers or log-in credentials were compromised and less than one percent of Social Security numbers were compromised. In addition, the outside individual who took the data was captured by the FBI. The government has stated they believe the data has been recovered and that there is no evidence the data was used for fraud or shared by this individual.
The largest category of information accessed was information on consumers and small businesses as of the time they applied for one of our credit card products from 2005 through early 2019. This information included personal information Capital One routinely collects at the time it receives credit card applications, including names, addresses, zip codes/postal codes, phone numbers, email addresses, dates of birth, and self-reported income.
Beyond the credit card application data, the individual obtained portions of credit card customer data, including:
This information has been shared on Capital One’s website, servicing portal, press release and 8K filing.
The individual also obtained the following data:
We have notified these customers through the mail.
For our Canadian credit card customers, approximately 1 million Social Insurance Numbers were compromised in this incident. We have notified all Canadian customers affected.
For our Canadian credit card customers, please visit our website at www.capitalone.ca/facts2019.
What happened?
On July 19, 2019, we determined that an outside individual gained unauthorized access and obtained certain types of personal information about Capital One credit card customers and individuals who had applied for our credit card products.
We immediately fixed the issue and promptly began working with federal law enforcement. The outside individual who took the data was captured by the FBI. The government has stated they believe the data has been recovered and that there is no evidence the data was used for fraud or shared by this individual.
How did you discover the incident?
Like many companies, we have a Responsible Disclosure Program which provides an avenue for ethical security researchers to report vulnerabilities directly to us. The configuration vulnerability was reported to us by an external security researcher through our Responsible Disclosure Program on July 17, 2019. We then began our own internal investigation, leading to the July 19, 2019, discovery of the incident.
When did this occur?
On July 19, 2019, we determined that an outside individual gained unauthorized access and obtained certain types of personal information about Capital One credit card customers and individuals who had applied for our credit card products. This occurred on March 22 and 23, 2019.
How do I know if I’ve been impacted?
The outside individual who took the data was captured by the FBI. The government has stated they believe the data has been recovered and that there is no evidence the data was used for fraud or shared by this individual.
We have directly notified by mail the U.S. individuals whose Social Security numbers or linked bank account numbers were accessed. We also have notified all Canadian customers affected. Canadian customers can find more information at www.capitalone.ca/facts2019 or www.capitalone.ca/facts2019/fr.
Who is responsible for this cyber incident?
The outside individual who took the data was captured by the FBI. The government has stated they believe the data has been recovered and that there is no evidence the data was used for fraud or shared by this individual.
Does this incident impact customers from your other businesses?
This incident primarily impacted people who have applied for one of our credit card products as well as credit card customers. Our Auto Finance, Commercial Bank, and customers from our UK card businesses were not impacted.
What is Capital One doing to protect me after this incident?
We have sophisticated fraud systems in place to detect any unusual activity and protect our customers from unauthorized actions.
We have notified by mail the U.S. individuals whose Social Security numbers or linked bank account numbers were accessed. We also have notified all Canadian customers affected. Canadian customers can find more information at www.capitalone.ca/facts2019 or www.capitalone.ca/facts2019/fr.
Customers are encouraged to enroll in credit card account alerts to help them keep track of activity on their accounts. Customers can sign in to online banking and set up text or email alerts, based on their preferences.
Additionally, we encourage customers to monitor their credit card accounts for unusual or suspicious activity and, if they notice any activity that they do not recognize, to call the number on the back of their Capital One card or on their statement as soon as possible.
Are there any additional steps that I can take to protect myself against fraud and identity theft?
You can request a free copy of your credit report once every 12 months from each of the three national credit reporting agencies: Equifax, Experian and TransUnion.
To obtain free credit reports, simply visit www.annualcreditreport.com, call 1-877-322-8228, or complete the Annual Credit Report Request Form, which can be found here, and mail it to: Annual Credit Report Request Service, P.O. Box 105281, Atlanta, GA 30348-5281.
Additionally, you can call the toll-free fraud number of any one of the three nationwide credit bureaus and place an initial or extended fraud alert on your credit report.
An initial fraud alert stays on your credit report for one year and acts as an alert to potential lenders. An extended fraud alert is intended for victims of identity theft and stays on your credit report for seven years.