Capita Fined £14 Million After Data Breach Exposes 6.6 Million Users
The United Kingdom's Information Commissioner's Office (ICO) has levied a £14 million penalty on Capita following a significant cyber attack in March 2023. This breach exposed the personal data of approximately 6.6 million individuals.
The United Kingdom's Information Commissioner's Office (ICO) has levied a £14 million penalty on Capita following a significant cyber attack in March 2023. This breach exposed the personal data of approximately 6.6 million individuals.
The penalty was divided between Capita plc, which was fined £8 million, and its subsidiary, Capita Pension Solutions Limited, which received a fine of £6 million.
The breach compromised sensitive data, including pension records, staff information, and customer details from more than 600 organizations that Capita supports. For many victims, the stolen data included financial information, criminal records, and other personal details.
The attack notably impacted pension scheme providers, with data exposure affecting 325 organizations through Capita Pension Solutions Limited.
The cyber attack originated when an employee inadvertently downloaded a malicious file on March 22, 2023. Although Capita's security systems issued a high-priority alert within ten minutes, the company delayed 58 hours before isolating the infected device.
This delay allowed the attackers to spread malicious software throughout the network, gain administrator access, and navigate freely between systems. Between March 29 and 30, the attackers extracted nearly one terabyte of data from Capita's systems.
The United Kingdom's Information Commissioner's Office (ICO) has levied a £14 million penalty on Capita following a significant cyber attack in March 2023.
On March 31, the attackers deployed ransomware and reset all user passwords, effectively locking Capita staff out of their network. The ICO received a minimum of 93 complaints from individuals affected by this security lapse.
The ICO's investigation revealed significant deficiencies in Capita's security measures. The company failed to implement adequate controls for administrative accounts, enabling the attackers to escalate their privileges and access critical systems across multiple domains. This vulnerability had been previously identified on three occasions but was not addressed.
Capita's Security Operations Centre was understaffed and frequently missed its target response time of one hour for security alerts. For at least six months preceding the incident, the team consistently failed to meet these deadlines.
Additionally, Capita performed penetration testing only when systems were first established and did not conduct follow-up tests, even for systems managing millions of sensitive records.
The ICO initially proposed a £45 million fine for Capita but reduced the penalty to £14 million after considering the company's response efforts.
Capita offered affected customers 12 months of complimentary credit monitoring through Experian and established a dedicated support call center. Over 260,000 individuals activated the credit monitoring service.
John Edwards, the UK Information Commissioner, highlighted the necessity for organizations of all sizes to prioritize cybersecurity. He noted that the breach's magnitude could have been mitigated with appropriate security measures, emphasizing that cyber criminals do not wait, and businesses cannot afford to delay in safeguarding customer data.
Based on reporting by GBHackers.
