ICO fines Capita £14m after ransomware caused major data breach

Capita has been fined £14m for its failure to secure personal data, which led to millions of people’s information being stolen after a Black Basta ransomware cyber attack in March 2023.

The Information Commissioner’s Office (ICO), which imposed the fine, said six million people had been affected by the data breach, with the information stolen including pension and staff records and details of Capita’s customers.

The cost of the breach to Capita could rise because thousands of affected individuals are involved in legal action against the outsourcing services provider.

The cyber attack was subsequently claimed by the Black Basta ransomware crew, which listed Capita on its dark web leak site and published documents that appeared to have been stolen from its systems, including client information.

The incident caused major IT outages and had a significant impact on customer-facing services at many public sector bodies and some operators of critical national infrastructure across the UK, with staff left unable to take calls from members of the public and others falling back on traditional pen and paper. A total of 325 organisations, which are customers of Capita, were impacted by the data breach, said the ICO.

The ICO fined Capita plc £8m and Capita Pension Solutions £6m for failing to ensure the security of processing of personal data, which left it at significant risk. It added that the company did not have the “appropriate technical and organisational measures” to respond effectively.

UK information commissioner John Edwards said: “Capita failed in its duty to protect the data entrusted to it by millions of people. The scale of this breach and its impact could have been prevented had sufficient security measures been in place.

“When a company of Capita’s size falls short, the consequences can be significant. Not only for those whose data is compromised – many of whom have told us of the anxiety and stress they have suffered – but for wider trust amongst the public and for our future prosperity. As our fine shows, no organisation is too big to ignore its responsibilities.”

This fine, and mounting legal proceedings, should be a wake-up call to any firm still playing fast and loose with its customers’ data Adnan Malik, Barings Law

The ICO initially planned to fine Capita £45m, but the fine was reduced after the business submitted representations and mitigating factors, including improvements it made following the attack, support offered to affected individuals and engagement with other regulators.

The attack began when a malicious file was unintentionally downloaded onto an employee’s device. Capita’s failure to quarantine the device for 58 hours meant the attacker was able to exploit its systems.

Adnan Malik, head of data protection at Barings Law, which is undertaking legal action on behalf of thousands of affected individuals against Capita, said the ICO fine represents less than 1% of Capita’s annual revenue, which last year exceeded £2bn.

“It does little to set right the harms caused by the firm’s inadequate cyber security procedures, which led to the loss of highly sensitive data, including benefits and pension records,” added Malik.

The ICO fine is separate to Barings Law’s legal action against Capita, and changes nothing about its ongoing claim,” added Malik. “If anything, we would expect that this will mean our case progresses more quickly.”

He said there are increasing data breaches against major firms, which are incredibly damaging to people’s finances, privacy and trust. “This fine, and mounting legal proceedings, should be a wake-up call to any firm still playing fast and loose with its customers’ data.”

Source

Shopping Cart
Shopping cart34
eco4life Smart LED light extension strip - LS312
-
+
eco4life Smart Security Starter Kit - EK5HWPT
-
+
(Refurbished) Logitech Wireless Headset H600
-
+
(Refurbished)  ASTRO Gaming A10 Wired Gaming Headset
-
+
eco4life Smart Wi-Fi Outdoor Outlet Plug - DPS5108D
-
+
Aluratek ASHBC01F Eco4life 720p SmartHome Battery-Powered Outdoor Wi-Fi Security Camera
-
+
HGST 8TB 3.5" SATA Recertified HDD W0F23666
-
+
eco4life Smart Wi-Fi LED Light Bulb E26 - DBEQPW30
-
+
eco4life Wi-Fi Smart IP Indoor Camera 1080P - 9C
-
+
Monoprice 12Vdc to 100Vdc 100W Auto Power Invertor with Dual USB Charger (2100mA)
-
+
LiNKe 30W Dual USB Smart Wall Charger
-
+
(Refurbished) Astro A20 Wireless Headset
-
+
WD 3TB 3.5" WD3000F9YZ SATA Recertified HDD
-
+
LiNKe 60W 6-Port Smart Car Charger with Quick Charge 3.0 Port
-
+
Aluratek eco4life Smart Home WiFi Outlet Plug
-
+
GabbaGoods Picture Perfect 4000 mAh Power Bank GG-PBPI-WHT
-
+
eco4life Smart Light Switch - KS602S
-
+
eco4life Smart LED light strip - LS300
-
+
eco4life ASHPS05F SmartHome Wi-Fi Power Surge Strip
-
+
(Refurbished) Logitech Wireless Keyboard K360
-
+
Antec Prizm 120 ARGB 120mm Case Fans w/Fan Controller Single
-
+
(Open Box) Logitech MK360 Full-size Wireless Scissor Keyboard and Mouse - Black
-
+
(Refurbished) Logitech H151 Stereo Headset
-
+
(Refurbished) Logitech Stereo Headset H111
-
+
WD Black SN850X 1 TB Solid State Drive - M.2 2280 Internal - PCI Express NVMe (PCI Express NVMe x4) (Recertified)
-
+
(Refurbished) Logitech G432 7.1 Surround Sound Gaming Headset
-
+
Subtotal
$1,298.05
Total
$1,318.04
Continue shopping
34
Scroll to Top