The UK Information Commissioner's Office (ICO) imposed a record £14 million fine on Capita, the country's largest outsourcing company, following a major cyberattack in 2023 that compromised the personal data of 6.6 million people. The penalty was split between Capita plc (£8 million) and Capita Pension Solutions Limited (£6 million), reflecting the widespread impact across both the parent company and its pension subsidiary. The breach affected 325 out of more than 600 organizations that rely on Capita’s services, exposing sensitive information such as bank and credit card details, biometric data, passport information, login credentials, and even child data. For some individuals, the stolen data included details of criminal records, financial information, and other special category data. The ICO’s investigation found that Capita failed to implement adequate technical and organizational measures to secure personal data, leaving it vulnerable to attack and unable to respond effectively when the breach occurred. The attack began when a malicious JavaScript file was downloaded onto an employee’s device on March 22, 2023, but the compromised device was not quarantined for 58 hours, allowing attackers to access and exfiltrate data. Capita initially claimed there was no evidence of data compromise, but subsequent findings contradicted this, revealing the extent of the breach. The ICO originally considered a much higher fine of £45 million, but reduced the amount after Capita demonstrated improvements in security, provided support to victims, and cooperated with authorities including the National Cyber Security Centre. The breach led to significant anxiety and stress among affected individuals, with some reporting financial losses. Despite the incident, Capita continued to secure substantial government contracts, with 241 contracts worth £6 billion awarded since the breach. The ICO emphasized that no organization is too large to be held accountable for data protection failures and highlighted the importance of proactive cybersecurity measures. The fine represents approximately 12 percent of Capita’s 2024 post-tax profits, underscoring the financial and reputational consequences of inadequate data security. The incident serves as a stark reminder to all organizations of the critical need to safeguard personal data and maintain robust incident response capabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On 15 October 2025, the ICO announced a £14 million fine against Capita for inadequate security measures and privacy violations connected to the March 2023 cyberattack. The regulator said the breach affected 6.6 million people and highlighted failures such as poor privileged access controls, insufficient remediation of known issues, and delayed incident response.
During its investigation, the UK Information Commissioner's Office initially proposed fining Capita £45 million for security and privacy failings tied to the 2023 attack. The proposed amount was later reduced after considering Capita's remedial actions, cooperation, and acceptance of liability.
In May 2023, Capita said the financial impact of recovering from the cyberattack could total about £20 million. The estimate reflected the scale of remediation and operational disruption following the breach.
By 20 April 2023, Capita confirmed that its systems had been breached and that data had been stolen. This marked a significant escalation from its earlier public messaging about the incident.
Researchers observed Capita briefly appear on Black Basta's Tor-based leak site on 8 April 2023. This public listing signaled that the ransomware group was claiming responsibility and threatening to leak stolen data.
On 3 April 2023, Capita publicly addressed the incident but initially downplayed its impact. Later reporting said the company had not yet fully acknowledged the extent of system compromise and data theft.
The attackers ultimately deployed ransomware on 31 March 2023, attempting encryption on at least 1,057 hosts. The incident also forced a global password reset affecting 59,359 accounts and disrupted access to systems.
During late March 2023, the intruders used tools including Cobalt Strike, Bloodhound, SystemBC, and Rclone to conduct reconnaissance, traverse at least eight domains, and steal roughly 975 GB to 1 TB of data. The exposed data related to about 6.6 million people across 325 customer organizations.
Capita's endpoint detection and response tooling reportedly detected the attack within 10 minutes, including a high-severity alert on 22 March 2023. However, the infected device was not isolated for about 58 hours, allowing the attacker to establish persistence, move laterally, and escalate privileges.
In March 2023, the Capita incident began when an employee downloaded a malicious JavaScript file, believed to be a drive-by download. The malware chain installed Qakbot and Cobalt Strike, giving the attacker an initial foothold.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
blog.bushidotoken.net
Open sourcego.theregister.com
Open sourceico.org.uk
Open sourcebleepingcomputer.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.