Anne Bucher  |  June 22, 2020

Category: Data Breach

Top Class Actions’s website and social media posts use affiliate links. If you make a purchase using such links, we may receive a commission, but it will not result in any additional charges to you. Please review our Affiliate Link Disclosure for more information.

Woman using credit card regarding the Capitol One data breach class action lawsuit filed

Capital One and Amazon’s failure to adequately safeguard credit card holders’ personal data allowed it to be compromised in a 2019 data breach, according to a class action lawsuit filed in the Superior Court of Québec.

Not only did the defendants fail to safeguard against the Capital One credit card data breach, they also failed to provide timely notification to those who were affected, the Capital One data breach class action lawsuit says. The data theft reportedly occurred on March 22 and 23, 2019 and was initially discovered on July 17, 2019. However, the data breach was not disclosed to the public until July 29, 2019.

“This case involves one of the biggest data security breaches in history,” the Capital One data breach class action lawsuit states.

Capital One has collected massive amounts of data on its customers since 2005. To store and mine this data, it had created a massive data centre that it would spend significant amounts of money to upgrade, maintain and secure.

“Class Members entrusted their most sensitive data — data that could be used by a miscreant to assume those customers’ identities — to a bank and cloud computing company based on their reasonable belief that it would be safe and secure,” the Capital One data breach class action lawsuit alleges.

“Capital One and Amazon thoroughly monetized (and continue to monetize) sensitive Capital One Customer data, mining it for every edge and insight about their behaviours.”

Capital One decided the cost of maintaining a data centre was too high and decided to utilize Amazon’s AWS public cloud to store and process customer data in 2015. This system allowed Capital One to buy only as much computing power and storage as it needed. It also allowed the credit card company to take advantage of Amazon’s machine learning tools and data scientists.

“Unfortunately, there were serious problems with using AWS to mine customer data,” the data breach class action lawsuit says. “Most importantly, the machine learning models required massive amounts of historical data and if the data was insufficient, the models would not be accurate.”

According to the data breach class action lawsuit, Capital One created massive repositories of customer data that included “data retained far in excess of customer expectations.”

Unlike other large financial institutions that prioritized the security of customer data, Capital One elected to provide customers’ sensitive data to a public cloud provider. At the same time, Amazon was looking for a large financial institution to sign on to the AWS ecosystem to signal to other financial institutions that it was safe to put their data in the public cloud.fingers on keyboard with social icons regarding the Capital One data breach class actin lawsuit

Because it was widely known that AWS suffered from a security flaw, Capital One created software that it jointly marketed with Amazon to misleadingly reassure customers, regulators and the public that the data would be protected. However, this software reportedly failed to safeguard the data as promised.

The data breach reportedly affects information that was collected at the time individuals and small businesses applied for a Capital One credit card between 2005 and 2019. The information compromised in the data breach may include: names, addresses, postal codes, phone numbers, email addresses, birthdates, credit card application data, and other customer data.

According to the data breach class action lawsuit, Capital One and Amazon together “orchestrated a massive migration of highly-sensitive data” to a public AWS cloud from Capital One’s private cloud. Together, Amazon and Capital One allegedly misled customers, regulators and members of the public by claiming the data was being protected. However, the Capital One data breach class action lawsuit says these assurances are “indisputably false and/or misleading.”

Capital One credit card holders and applicants who reside in Quebec and whose personal information was compromised in the Capital One credit card data breach incident that occurred on March 22-23, 2019 are included as potential Class Members of this data breach class action lawsuit.

Approximately 100 million U.S. residents and 6 million Canadians were likely impacted by the Capital One credit card data breach. Additionally, about 1 million social insurance numbers were compromised.

The Capital One data breach class action lawsuit asks a judge to order the defendants to implement safeguards to prevent and detect unauthorized access to private information, and offer compensatory and punitive damages to Class Members.

A similar Capital One credit card data breach class action lawsuit has been filed in Calgary.

Do you have a Capital One credit card? Are you worried about your personal information being exposed in this data breach? Tell us your thoughts in the comment section below! 

The plaintiffs are represented by Jeff Orenstein of Consumer Law Group Inc.

The Capital One Data Breach Class Action Lawsuit is M. Royer, et al. v. Capital One Bank (Canada Branch), et al., Case No. 500-06-001010-194, in the Superior Court of Québec, Canada. 

We tell you about cash you can claim EVERY WEEK! Sign up for our free newsletter.

  • This field is for validation purposes and should be left unchanged.


36 thoughts onCapital One Data Breach Class Action Lawsuit Says Millions Were Impacted

  1. Maria Frencheater says:

    I haven’t received a letter but I got a Gmail if that counts stating that I was a member of the class action lawsuit and I do believe so as well how to apply

  2. Kimberly Minty says:

    I have received a letter from Capital One informing me that all my information was leaking their data breach I still have the letter I left the comment I believe in 2019 as well

    I have already left the comment about the Capital One data breach in CANADA I have nothing but problems my bank account keeps getting compromised with missing money on an ongoing basis I’ve got letters from creditors tell me that I owe $26,000 on credit cards I’ve never had the list goes on and on I have been contacted by Capital One and they let me know that all my information was leaked in their data breach my social insurance number birthday bank accounts addresses name everything they could get they got they offered me one year credit not credit monitoring to ensure everything would be okay I don’t understand how they can say that when I’ve had nothing but problems I have stuff on my credit report that is not mine my credit score has been below average since this has happened I just like to know when they’re going to be held accountable for things that they’ve done to Canadian citizens like this is insane I don’t think I’d ever get my credit back up or anything and I’m tired of these people call me and tell me I owe them money I just tell them it’s not me maybe it’s my daughter-in-law Kim I don’t know what to say anyways I’m sure I’ve already fought filled out a claim form at least I hope I have thank you

    1. Kimberly Minty says:

      Sorry I meant to say that I left a comment in 2020 not 19 I do believe that the US class action suit against Capital One are filing out claim forms I don’t know where Canada stands at this point if anybody has information about filling out claim forms or how we do that it would be wonderful if you can inform me how to go about doing that thank you

  3. Danijela says:

    Can someone provide an update on this? I signed up for the class action as I received a letter stating my information, including my sin number may have been breached.

  4. Leslie White says:

    I received the letter stating I was involved in this breach of data and that my information may have been leaked out. Since then I have noticed suspicious things going on with an old PayPal account I no longer use as well as many text and phone calls from some scams from a US number claiming I need to come to the airport and pick up money I received in a lawsuit that was settled due to someone using my email address illegally. Can someone please contact me regarding these issues please. I did register with a law firm . I live in the Fraser Valley area of BC
    Thank you leslie white

Leave a Reply

Your email address will not be published. By submitting your comment and contact information, you agree to receive marketing emails from Top Class Actions regarding this and/or similar lawsuits or settlements, and/or to be contacted by an attorney or law firm to discuss the details of your potential case at no charge to you if you qualify. Required fields are marked *

Please note: Top Class Actions is not a settlement administrator or law firm. Top Class Actions is a legal news source that reports on class action lawsuits, class action settlements, drug injury lawsuits and product liability lawsuits. Top Class Actions does not process claims and we cannot advise you on the status of any class action settlement claim. You must contact the settlement administrator or your attorney for any updates regarding your claim status, claim form or questions about when payments are expected to be mailed out.