Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Capita To pay £14 Million For Data Breach Exposes 6.6 Million Users Personal Data

Posted on October 16, 2025October 16, 2025 By CWS

The UK’s Data Commissioner’s Workplace (ICO) has imposed a £14 million effective on outsourcing big Capita following a serious cyber assault in 2023 that uncovered the private information of 6.6 million people.

This penalty, cut up as £8 million to Capita plc and £6 million to Capita Pension Options Restricted, marks one of many largest information safety fines in current UK historical past.

The breach highlighted essential shortcomings in company cybersecurity, affecting pension schemes and delicate private data throughout a whole bunch of organizations.

The incident unfolded on March 22, 2023, when an worker unwittingly downloaded a malicious file onto an organization machine, granting hackers preliminary entry to Capita’s community.

Regardless of a high-priority safety alert triggering inside 10 minutes and a few automated responses activating, Capita did not isolate the contaminated machine for 58 hours, far exceeding their one-hour goal response time.

This delay allowed the attackers to deploy malware, escalate privileges, and transfer laterally throughout programs, exfiltrating practically one terabyte of information between March 29 and 30.

By March 31, ransomware was deployed, resetting consumer passwords and locking Capita employees out of their programs, which disrupted companies for purchasers, together with native councils, the NHS, and pension suppliers.

Capita Knowledge Breach Exposes Delicate Knowledge

The stolen information encompassed pension information, employees particulars, and buyer data from over 600 organizations, with 325 pension schemes immediately impacted.

Delicate components included monetary information, prison information, and particular class data reminiscent of well being or ethnic particulars for some victims.

The ICO obtained a minimum of 93 complaints from affected people reporting nervousness and stress over potential identification theft and fraud.

The ICO’s probe uncovered a number of failures in Capita’s information safety practices, violating UK GDPR necessities for safe processing.

Notably, Capita lacked a tiered administrative account mannequin, enabling straightforward privilege escalation and unauthorized community traversal vulnerabilities flagged in prior assessments however unaddressed.

Their Safety Operations Centre was chronically understaffed, constantly lacking response targets for alerts within the months main as much as the assault.

Moreover, essential programs dealing with hundreds of thousands of information underwent penetration testing solely at commissioning, with no follow-ups, and findings remained siloed inside enterprise items slightly than organization-wide.

These lapses left huge quantities of non-public information uncovered to important danger, amplifying the breach’s scale.

Data Commissioner John Edwards emphasised that “Capita failed in its obligation to guard the information entrusted to it by hundreds of thousands of individuals,” underscoring the preventable nature of the incident by fundamental measures just like the precept of least privilege and well timed alert responses.

Initially dealing with a £45 million provisional effective, Capita negotiated it right down to £14 million through a voluntary settlement, admitting legal responsibility with out attraction.

Capita supplied 12 months of free credit score monitoring to affected people by Experian, with over 260,000 activations, and established a devoted help hotline.

CEO Adolfo Hernandez acknowledged the occasion as a part of a wave of assaults on UK companies, reaffirming commitments to information safety for private and non-private sector purchasers.

The ICO urged organizations to observe NCSC steering on stopping lateral motion, conduct common danger assessments, and prioritize safety staffing.

With ongoing authorized actions from victims, Capita’s whole prices could but rise, emphasizing accountability in an period of escalating ransomware threats.

Observe us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Breach, Capita, Data, Exposes, Million, Pay, Personal, Users

Post navigation

Previous Post: Beware the Hidden Costs of Pen Testing
Next Post: US Charges Cambodian Executive in Massive Crypto Scam and Seizes More Than $14 Billion in Bitcoin

Related Posts

APT36 Hackers Attacking Indian Government Entities to Steal Login Credentials Cyber Security News
Microsoft, SentinelOne, and Palo Alto Networks Withdraw from 2026 MITRE ATT&CK Evaluations Cyber Security News
Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials Cyber Security News
Electronic Arts Blocked 300,000 Attempts Following Battlefield 6 Beta Launch Cyber Security News
Microsoft Teams New Premium Feature Blocks Screenshots and Recordings During Meeting Cyber Security News
New Multi-Stage Tycoon2FA Phishing Attack Now Beats Top Security Systems Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Personal Information Compromised in Freedom Mobile Data Breach
  • 5 Threats That Reshaped Web Security This Year [2025]
  • Marquis Data Breach Impacts Over 780,000 People
  • Hackers Using Evilginx to Steal Session Cookies and Bypass Multi-Factor Authentication Tokens
  • New ‘Sryxen’ Stealer Bypasses Chrome Encryption via Headless Browser Technique

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Personal Information Compromised in Freedom Mobile Data Breach
  • 5 Threats That Reshaped Web Security This Year [2025]
  • Marquis Data Breach Impacts Over 780,000 People
  • Hackers Using Evilginx to Steal Session Cookies and Bypass Multi-Factor Authentication Tokens
  • New ‘Sryxen’ Stealer Bypasses Chrome Encryption via Headless Browser Technique

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark