{"id":3283,"date":"2025-10-19T06:03:26","date_gmt":"2025-10-19T06:03:26","guid":{"rendered":"http:\/\/ft365.org\/index.php\/2025\/10\/19\/capita-fined-14m-after-2023-breach-that-hit-6-6-million-people\/"},"modified":"2025-10-19T06:03:26","modified_gmt":"2025-10-19T06:03:26","slug":"capita-fined-14m-after-2023-breach-that-hit-6-6-million-people","status":"publish","type":"post","link":"http:\/\/ft365.org\/index.php\/2025\/10\/19\/capita-fined-14m-after-2023-breach-that-hit-6-6-million-people\/","title":{"rendered":"Capita Fined \u00a314m After 2023 Breach that Hit 6.6 Million People"},"content":{"rendered":"<div>\n<p><img decoding=\"async\" src=\"http:\/\/ft365.org\/wp-content\/uploads\/2025\/06\/localimages\/ea721ff9-8ba4-4d88-b386-57e9e1606077.jpg?width=64&#038;height=64&#038;mode=crop&#038;scale=both&#038;format=webp\" alt=\"Photo of Phil Muncaster\" loading=\"lazy\"><\/p>\n<\/div>\n<div id=\"cphContent_pnlArticleBody\">\n<div id=\"layout-130d9fa1-3caf-47da-b62c-ccf7185bd5ea\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>Capita will not appeal a \u00a314m regulatory penalty for security failings that led to a 2023 data breach impacting nearly seven million people, according to the\u00a0Information Commissioner\u2019s Office (ICO).<\/p>\n<p>The UK data protection regulator said it initially intended to fine the outsourcing giant \u00a345m. However, it decided that improvements made by Capita after the attack, support offered to affected individuals, and engagement with other regulators and the National Cyber Security Centre (NCSC) were enough to reduce the penalty by 69%.<\/p>\n<p>In March 2023, a Capita employee unwittingly downloaded malware to their device after being targeted by a threat actor working with the Black Basta ransomware group.<\/p>\n<p>Although a \u201chigh priority security alert\u201d was raised within 10 minutes, the device wasn\u2019t quarantined for a further 58 hours, enabling the threat actor to escalate privileges and move laterally to other parts of the network, according to the ICO.<\/p>\n<p>Nine days after the initial breach, on March 31 2023, ransomware was deployed on the Capita network and the threat actor changed all user passwords, locking employees out.<\/p>\n<p>Data stolen\u00a0by Black Basta included pension and staff records, and sensitive information belonging to customers of Capital clients \u2013 such as criminal records, financial data and special category data, the ICO said. Over half (325) of the 600 Capita Pension Solutions clients were impacted.<\/p>\n<p>Last year 8000 claimants brought a High Court case against Capita.<\/p>\n<p>The company also ran billions of pounds worth of government contracts at the time, for clients including the NHS, HM Prison and Probation Service, the Royal Navy and many others.<\/p>\n<h2>A Catalog of Errors<\/h2>\n<p>According to the ICO, Capita infringed the UK GDPR by failing to \u201cimplement appropriate technical and organisational measures\u201d such as:<\/p>\n<ul>\n<li>Failing to prevent privilege escalation and unauthorised lateral movement: There was no \u201ctiering model\u201d (a key tenet of privileged access management) for admin accounts, despite this oversight being flagged on several occasions<\/li>\n<li>Failing to respond appropriately to security alerts: Capita took 58 hours to respond despite a target response time of just one hour, which was partly due to understaffing in its Security Operations Center (SOC)<\/li>\n<li>Inadequate pen testing and risk assessment: Systems processing millions of records were only given one pen test after being commissioned\u00a0and findings were siloed in business units so identified risks weren\u2019t addressed across the business<\/li>\n<\/ul>\n<p>Information commissioner, John Edwards, argued that the incident could have been prevented had \u201csufficient security measures\u201d been put in place.<\/p>\n<p>\u201cWhen a company of Capita\u2019s size falls short, the consequences can be significant. Not only for those whose data is compromised \u2013 many of whom have told us of the anxiety and stress they have suffered \u2013 but for wider trust amongst the public and for our future prosperity,\u201d he continued.<\/p>\n<p>\u201cAs our fine shows, no organization is too big to ignore its responsibilities.\u201d<\/p>\n<p>Responding to the news, Capita CEO Adolfo Hernandez stressed the \u201ccybersecurity transformation\u201d that the business has undergone since the incident.<\/p>\n<p>\u201cAs a result, we have hugely strengthened our cybersecurity posture, built in advanced protections and embedded a culture of continuous vigilance,\u201d he said in a statement.\u00a0<\/p>\n<p>\u201cFollowing an extended period of dialogue with the ICO over the last two years, we are pleased to have concluded this matter and reach today\u2019s settlement.\u201d<\/p>\n<p>The ICO urged\u00a0organizations to proactively address security risks by:<\/p>\n<ul>\n<li>Ensuring least privilege principles are enforced\u00a0and taking other steps to prevent lateral movement<\/li>\n<li>Regularly monitoring for suspicious activity and responding promptly to alerts<\/li>\n<li>Sharing the findings of pen tests across the entire organization<\/li>\n<li>Prioritizing investment in key controls to ensure they\u2019re working properly<\/li>\n<li>Checking \u201cagreements and responsibilities\u201d between data controllers and processors<\/li>\n<\/ul><\/div>\n<p>Image\u00a0credit: Ahyan Stock Studios \/ Shutterstock.com<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Capita will not appeal a \u00a314m regulatory penalty for security failings that led to a 2023 data breach impacting nearly seven million people, according to the\u00a0Information Commissioner\u2019s Office (ICO). The UK data protection regulator said it initially intended to fine the outsourcing giant \u00a345m. However, it decided that improvements made by Capita after the attack<\/p>\n","protected":false},"author":2,"featured_media":3284,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3283","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3283-3bd26339-5e80-4e0d-b730-c664a29e1b63.jpg",300,300,false],"thumbnail":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3283-3bd26339-5e80-4e0d-b730-c664a29e1b63-150x150.jpg",150,150,true],"medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3283-3bd26339-5e80-4e0d-b730-c664a29e1b63.jpg",300,300,false],"medium_large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3283-3bd26339-5e80-4e0d-b730-c664a29e1b63.jpg",300,300,false],"large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3283-3bd26339-5e80-4e0d-b730-c664a29e1b63.jpg",300,300,false],"1536x1536":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3283-3bd26339-5e80-4e0d-b730-c664a29e1b63.jpg",300,300,false],"2048x2048":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3283-3bd26339-5e80-4e0d-b730-c664a29e1b63.jpg",300,300,false],"morenews-featured":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3283-3bd26339-5e80-4e0d-b730-c664a29e1b63.jpg",300,300,false],"morenews-large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3283-3bd26339-5e80-4e0d-b730-c664a29e1b63.jpg",300,300,false],"morenews-medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3283-3bd26339-5e80-4e0d-b730-c664a29e1b63.jpg",300,300,false],"crawlomatic_preview_image":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/10\/3283-3bd26339-5e80-4e0d-b730-c664a29e1b63-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"http:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"http:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/3283","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=3283"}],"version-history":[{"count":0,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/3283\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/3284"}],"wp:attachment":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=3283"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=3283"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=3283"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}