In announcing the data breach, Capital One emphasised that no credit card numbers or log-in credentials were compromised, nor was the vast majority of Social Security numbers on the affected applications.
It is unusual in a major hacking case for a suspect to be apprehended so quickly, and in this case, that was apparently due to boasts made online.
Thompson, who authorities say used the name "erratic" in online conversations, is suspected of "exfiltrating and stealing information, including credit card applications and other documents, from Capital One," according to a criminal complaint filed in federal court. She was ordered to remain in jail pending a detention hearing scheduled for Thursday, according to court records.
A lawyer for Thompson did not immediately respond to a message seeking comment.
Thompson "made statements on social media for evidencing the fact that she has information of Capital One, and that she recognises that she has acted illegally," according to the criminal complaint signed by FBI special agent Joel Martini.
In one online posting, "erratic" wrote: "I've basically strapped myself with a bomb vest, [expletive] dropping capitol ones dox and admitting it," according to the complaint.
"Although some of the information in those applications (such as Social Security numbers) has been tokenised or encrypted, other information including applicants' names, addresses, dates of birth and information regarding their credit history has not been tokenised," the FBI complaint said, and the bank told the bureau that the data includes "likely tens of millions of applications and approximately 77,000 bank account numbers."
Capital One, which is headquartered in the Washington suburb of McLean, Virginia, was alerted to a problem on July 17 after a person in an online discussion group had claimed to have taken large amounts of the company's data, according to the complaint.
The bank investigated and quickly confirmed there was a vulnerability, the court papers said.
The hacker was able to access the Social Security numbers of about 140,000 customers - those who used their Social Security number as their employer identification number in applying for small-business credit cards, the bank said.
Thompson previously worked at an unidentified cloud computing company that provided data services to Capital One, according to court papers.
Authorities said that, in conversations using the messaging service Slack, Paige posted a list of files she claimed to possess, leading another person in the group discussion to reply: "sketchy" and "don't go to jail plz."
The "erratic" user replied, "I wanna get it off my server that's why Im archiving all of it lol . . . its all encrypted," according to court files.
Based on other postings allegedly made by Thompson last month, the FBI came to suspect that she "intended to disseminate data stolen from victim entities, starting with Capital One," court documents say.