CSIDB logo
Incident

Capita plc

Incident posture

Attack window
Jan 2023
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2026-09-01 12:12

Linked entities

Victim
Capita plc
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack on the UK outsourcing firm Capita compromised the personal data of nearly seven million end customers, including members of 600 pension funds. The UK's Information Commissioner's Office identified multiple security failings at the company, including inadequate prevention of privilege escalation and unauthorized lateral movement, delayed responses to security alerts, and insufficient penetration testing and risk assessments. Following the incident, the regulator imposed a fine, reduced from an initial higher amount, which Capita chose not to appeal.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In October, the UK's Information Commissioner's Office (ICO) issued a £14m fine to outsourcing giant Capita plc for security failings that led to a massive ransomware breach in 2023. The incident impacted nearly seven million end customers, including members of 600 pension funds that were affected by the attack. The ICO pointed to a series of security errors at the outsourcer, which included the failure to prevent privilege escalation and unauthorized lateral movement, the failure to respond rapidly to security alerts, and inadequate pen testing and risk assessments. Capita chose not to appeal the penalty, which had been reduced from an initial £45m ($59m).

The 2023 ransomware breach affecting Capita plc represented one of the largest incidents tied to a UK outsourcer in recent years, with the scope of the compromise extending to nearly seven million end customers. Members of 600 pension funds were among those affected by the security incident, highlighting the breadth of the exposure across both direct customers and beneficiaries of pension schemes managed by the company. The ICO's investigation identified multiple specific security failings that contributed to the incident. These included the organization's failure to prevent privilege escalation and unauthorized lateral movement within its network, failures to respond rapidly to security alerts, and inadequate penetration testing and risk assessments. The regulator's findings indicated systemic deficiencies in Capita's security posture rather than a single isolated lapse.

The penalty imposed by the ICO was £14m, a substantial reduction from the initial £45m ($59m) figure that had been under consideration. Capita plc elected not to appeal the fine, effectively accepting the regulator's findings and the associated financial penalty. This decision to forgo an appeal distinguished Capita from other organizations facing regulatory action and resulted in the matter being resolved with the ICO. The outcome of the enforcement action placed Capita among the notable data breach penalties of 2025, reflecting the ICO's assessment of the seriousness of the security failings and the scale of the impact on affected individuals.

Sources

Sources available to members: 1 source.

CSIDB