From all reports, it was caused by an internal Capital One employee and was allowed due to misconfiguration on Capital One’s side.

AWS preaches the “Shared Security Model” and emphasizes what it is responsible for and what you are responsible for.

