Published • loading... • Updated
Capita Fined £14M After 58-Hour Delay Exposed 6.6M Records
Capita failed to quarantine a compromised device for 58 hours after a security alert, exposing 6.6 million records, including pension and staff data, the ICO said.
- Following its probe, the UK's data watchdog fined Capita �14million for failing to protect personal data after hackers stole information belonging to 6.6 million people during the March 2023 cyber attack.
- The breach began when an employee downloaded a malicious file on 22 March 2023, and Capita did not quarantine the device for 58 hours, allowing the attacker prolonged access.
- Forensics found ransomware on over 1,057 hosts and a global password reset of 59,359 accounts, while investigators say hackers removed pension and staff records.
- The ICO scaled back a proposed 45m fine to 14m after Capita Pension Solutions Limited improved security, supported victims, and engaged with regulators including the NCSC.
- Cyber-Security experts welcomed regulatory action as Trevor Dearing said, `Companies being held financially accountable for data protection failings is a good thing`, while Tussell data shows £6 billion in government contracts remain with Capita and the NCSC reported a 50% rise in attacks this year.
Insights by Ground AI
17 Articles
17 Articles

+4 Reposted by 4 other sources
Capita hit with £14m fine for personal data breach in 2023 cyber attack
Hackers stole personal information including pension details and staff records as well as details of customers of organisations Capita supports.
·London, United Kingdom
Read Full ArticleCoverage Details
Total News Sources17
Leaning Left2Leaning Right1Center4Last UpdatedBias Distribution57% Center
Bias Distribution
- 57% of the sources are Center
57% Center
L 29%
C 57%
14%
Factuality
To view factuality data please Upgrade to Premium