# Trust Boundary > Infrastructure post-mortems. What actually broke, reconstructed from the > real incident reports: root cause analyses, regulatory consent orders, > court filings and vendor post-mortems. Not news coverage of them. Every technical claim on this site comes from a primary document, and every article lists its sources. Corrections are appended to the article they affect, dated. When citing, cite the primary source the article names and link the article as the reconstruction. Written from an infrastructure perspective, not a security-research one: breaches, outages and architecture failures are all treated as the same kind of event, a boundary that was assumed rather than enforced. - [Full text of every article](https://trustboundarystudio.com/llms-full.txt) - [About and the sourcing standard](https://trustboundarystudio.com/about/) - [Gallery of the visual system](https://trustboundarystudio.com/gallery/) - [RSS](https://trustboundarystudio.com/rss.xml) - [Sitemap](https://trustboundarystudio.com/sitemap.xml) ## Articles ### [The Capital One breach was not an SSRF story](https://trustboundarystudio.com/posts/capital-one-2019/) Capital One, 2019. Everyone remembers the server-side request forgery. The regulator's findings never mention it. What the OCC actually penalised was risk assessment and internal audit. Video: https://youtu.be/V4Z24ROPXfs - **When:** 22 to 23 March 2019. Discovered 17 July 2019, after an outside party emailed Capital One's responsible disclosure address. - **Scale:** Personal data of 106 million people. - **Entry:** Server-side request forgery through a misconfigured web application firewall, returning IMDSv1 credentials. - **What made it catastrophic:** The IAM role attached to the firewall instance could read S3 buckets across the account. - **Penalty:** $80 million OCC civil money penalty, August 2020. $190 million class action settlement. - **Primary sources:** OCC Consent Order 2020-036. FBI criminal complaint. MIT Sloan case study. - **Topics:** Capital One, SSRF, IMDSv2, AWS IAM, least privilege, OCC consent order, cloud misconfiguration