The Information Commissioner’s Office (ICO) has issued a combined £14 million fine to Capita for failing to ensure the security of personal data related 2023 breach that saw hackers steal millions of people’s information.
The data watchdog fined parent company Capita plc £8 million, while Capita Pension Solutions Limited was slapped with a £6 million penalty. The ICO had initially intended to fine the firm £45 million, though it agreed to a voluntary settlement following engagement with the regulator.
In March 2023, the personal information of 6.6 million people was stolen by hackers when a malicious file was unintentionally downloaded onto an employee device.
According to the ICO, despite a high-priority alert being raised within ten minutes of the breach, and some immediate automated action being taken, Capita did not quarantine the device for 58 hours, giving the attacker time to exploit its systems.
The regulator said that this window allowed malicious software onto the Capita network, allowing the hacker to stay in the system, gain administrator permissions and access other areas of the network.
The result was that between 29 and 30 March 2023, nearly one terabyte of data was exfiltrated, including pension and staff records, as well as the details of customers in organisations Capita supports.
The ICO said that, for some people, this included sensitive information such as details of criminal records, financial data or special category data.
In total, 325 of the 600 organisations that Capita Pension Solutions Limited processes personal information for were impacted by the data breach, with the attacker then deploying ransomware and resetting all user passwords, preventing Capita staff from accessing their systems and network.
Over the course of its investigation, the ICO found that Capita had failed to ensure the security of processing of personal data, which left it at significant risk, and lacked the appropriate technical and organisational measures to effectively respond to the attack.
Among the most egregious risks the ICO identified was that Capita did not implement a tiering model for admin accounts, saying this allowed the attacker to escalate privileges, move laterally across multiple domains and compromise critical systems.
The watchdog said these failings were flagged as a vulnerability on at least three separate occasions but were not remedied.
Recommended
- ICO’s £7.5m Clearview AI Fine Back on Track After Ruling
- UK facing 4 major cyber-attacks each week, warns NCSC
- Glasgow and Edinburgh Councils Face ICO Reprimand
The investigation also found that Capita’s SOC was understaffed, meaning target times for responding to security alerts were routinely missed in the six months up to the hack, and that a lack of penetration testing amplified risks across the network.
“Capita failed in its duty to protect the data entrusted to it by millions of people. The scale of this breach and its impact could have been prevented had sufficient security measures been in place,” said John Edwards, UK Information Commissioner.
“When a company of Capita’s size falls short, the consequences can be significant. Not only for those whose data is compromised – many of whom have told us of the anxiety and stress they have suffered – but for wider trust amongst the public and for our future prosperity.
“As our fine shows, no organisation is too big to ignore its responsibilities.”





