The law firm Tycko & Zavareei has filed a lawsuit , related to of personal data of over 100 million customers of the Capital One banking holding, including information about about 140,000 social security numbers and 80,000 bank account numbers. In addition to Capital One, the defendants include GitHub, which is accused of providing the means for hosting, displaying, and using information obtained as a result of the hack.
According to the plaintiff, GitHub is required to comply with existing U.S. laws prohibiting the public posting of users' social security numbers. Specifically, as social security numbers have a fixed format, the company should have implemented filters to detect postings by users related to the leak and block them, without waiting for official notifications.
GitHub representatives stated that the plaintiff's claims are unfounded and that no personal data obtained from the leak was posted on GitHub. One repository only contained instructions on how to access data that actually remained in a database hosted on the Amazon S3 cloud service. Due to improper firewall configuration limiting access to web applications, there was a possibility of accessing the storage in Amazon S3. Upon the first notification from Capital One, the posted instructions were removed from GitHub.
As part of the proceedings, , a former employee of Amazon, has been arrested, who discovered the issue in March and posted information on GitHub in April on how to gain access. The details describing the issue remained on GitHub from April 21 until mid-July. Capital One is accused in the lawsuit of improper monitoring of unauthorized access, which led to the leak going unnoticed for almost three months.
Source: opennet.ru
