Capita said a March ransomware attack attributed to Black Basta compromised its Microsoft 365 environment and led to the theft of personal data from employees, customers, and clients. The outsourcing firm acknowledged that data was exfiltrated from less than 0.1% of its server estate, but the impact spread widely because Capita provides services to many organizations. Reporting indicated that customer data was stolen, and Capita notified affected customers, suppliers, and staff while working with forensic specialists and expanding remediation and security investments.
The breach triggered broad fallout across the UK. About 90 organizations reported personal data breaches to the Information Commissioner’s Office, and regulators contacted more than 300 pension funds to assess possible exposure. The Universities Superannuation Scheme warned that details for roughly 470,000 members may have been compromised, including names, dates of birth, National Insurance numbers, and pension membership numbers. Capita later said the incident would cost £20 million to £25 million, and by its annual results said the cyberattack had contributed to a loss of more than £106 million.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Capita later said the cyberattack contributed to an annual loss of more than £106 million. This marked a further financial escalation beyond the earlier £20 million to £25 million incident-cost estimate.
Capita said the March cyberattack was expected to cost £20 million to £25 million, as recovery and remediation continued. The company also confirmed Black Basta attribution, said less than 0.1% of its server estate was affected, and noted it could not yet estimate any regulatory fine.
Roughly 90 organizations submitted personal data breach reports to the UK Information Commissioner's Office following the Capita incident. The Pensions Regulator also contacted more than 300 pension funds to assess whether member data had been stolen.
The Universities Superannuation Scheme said personal data for about 470,000 members may have been compromised through Capita, which administers its pension services. USS advised members to assume the data was taken and said it would notify affected individuals and employers.
Capita acknowledged that customer, supplier, or colleague data may have been compromised during the March cyberattack. The company said some data had been exfiltrated and began contacting affected parties while continuing forensic investigation and remediation.
Capita experienced a company-wide IT outage on 2023-03-31 that disrupted employee access to Office365 services, including email and Teams, and affected some council phone lines. The incident prompted notification of the National Cyber Security Centre and the Cabinet Office amid concern over Capita's role in supporting critical UK public services.
Capita said the cyberattack began in March 2023. Attackers later identified as Black Basta compromised the company's Microsoft Office 365 environment and accessed data from a small portion of its server estate.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcetheguardian.com
Open sourcebbc.com
Open sourcetheguardian.com
Open sourcethetimes.com
Open sourcecomputerweekly.com
Open sourcetheguardian.com
Open sourcetheguardian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.