On July 29, 2019, Capital One disclosed that an attacker had exfiltrated over 100 million customer records from their AWS environment. The total cost including regulatory fines, class action settlement, remediation exceeded $300 million.

The breach required three conditions to be true simultaneously. An EC2 instance had IMDSv1 enabled, allowing the SSRF exploit to retrieve instance credentials from the metadata service. That instance had a public IP, making it reachable from the internet. The IAM role attached to the instance had permissions reaching sensitive data across S3 buckets containing customer records.

Each condition alone was a posture concern. Together, they were a catastrophe.

The question no cloud security tool in the market answers today: the day before the breach, when two of those three conditions were true and the third was about to become true, did anyone know?

What the market shows you