Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Capita To pay £14 Million For Data Breach Exposes 6.6 Million Users Personal Data

The UK's Information Commissioner's Office (ICO) has levied a £14 million fine on Capita due to a significant cyber attack in 2023 that compromised the personal data of 6.6 million individuals.

The UK's Information Commissioner's Office (ICO) has levied a £14 million fine on Capita due to a significant cyber attack in 2023 that compromised the personal data of 6.6 million individuals.

This fine is divided into £8 million for Capita plc and £6 million for Capita Pension Solutions Limited, marking one of the largest data protection fines in recent UK history.

The breach revealed critical deficiencies in corporate cybersecurity, impacting pension schemes and sensitive personal information across numerous organizations.

The incident began on March 22, 2023, when an employee inadvertently downloaded a malicious file onto a company device, allowing hackers initial access to Capita's network.

Despite a high-priority security alert activating within 10 minutes, Capita did not isolate the compromised device for 58 hours, significantly exceeding their one-hour target response time.

This delay permitted the attackers to deploy malware, escalate privileges, and access systems, extracting nearly one terabyte of data between March 29 and 30.

On March 31, ransomware was deployed, resetting user passwords and locking Capita staff out of their systems, disrupting services for clients, including local councils, the NHS, and pension providers.

The stolen data included pension records, staff details, and customer information from over 600 organizations, with 325 pension schemes directly affected.
Robert Langley · Thehackingpost

The stolen data included pension records, staff details, and customer information from over 600 organizations, with 325 pension schemes directly affected.

Exposed information included financial data, criminal records, and special category data such as health or ethnic details for some victims.

The ICO received at least 93 complaints from affected individuals regarding anxiety and stress over potential identity theft and fraud.

The ICO's investigation revealed multiple failures in Capita's data protection practices, violating UK GDPR requirements for secure processing.

Capita lacked a tiered administrative account model, which facilitated unauthorized network access, and its Security Operations Centre was understaffed, frequently missing response targets for alerts.

Advertisement

Critical systems handling extensive records underwent penetration testing only at commissioning, with no follow-ups, leaving significant amounts of personal data exposed to risk.

Capita initially faced a £45 million provisional fine but negotiated it to £14 million via a voluntary settlement, admitting liability without appeal.

Capita has offered 12 months of free credit monitoring to affected individuals, with over 260,000 activations, and established a dedicated support hotline.

The ICO recommends organizations adhere to NCSC guidance, regularly conduct risk assessments, and prioritize security staffing to mitigate similar risks.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories