Full Report
The Information Commissioner’s Office has fined Capita plc and Capita Pension Solutions Ltd a combined £14m following a cyber attack in April 2023 which saw hackers gain access to over 6m people’s data. Stroud News & Journal reports: Outsourcing giant Capita has been fined £14 million by the Information Commissioner’s Office (ICO) for failing to... Source
Analysis Summary
# Incident Report: Capita Personal Data Breach and Regulatory Fine
## Executive Summary
In March 2023, outsourcing giant Capita suffered a cyber attack resulting in the compromise and exfiltration of personal data belonging to 6.6 million individuals across various clients. The Information Commissioner’s Office (ICO) fined Capita plc and Capita Pension Solutions Ltd a combined £14 million for failing to adequately protect this personal data. The incident exposed sensitive information, including pension details, staff records, criminal records, and special category data.
## Incident Details
- **Discovery Date:** Not explicitly stated, but the ICO final penalty notice implies discovery and investigation followed the breach event.
- **Incident Date:** March 2023
- **Affected Organization:** Capita plc and Capita Pension Solutions Ltd
- **Sector:** Outsourcing/Business Services
- **Geography:** UK (Implied by ICO enforcement)
## Timeline of Events
### Initial Access
- **Date/Time:** Sometime prior to or in March 2023
- **Vector:** Attackers successfully exploited security vulnerabilities. (Specific attack vector not detailed in the summary text.)
- **Details:** Hackers gained unauthorized access to Capita's systems.
### Lateral Movement
- Details are not specified in the provided source, but the scale of the data loss suggests successful internal reconnaissance and network traversal.
### Data Exfiltration/Impact
- **What was stolen or damaged:** Personal data belonging to approximately 6.6 million individuals was stolen. This included pension details, staff records, financial data, details of criminal records, and special category data (e.g., race, religion, sexual orientation).
### Detection & Response
- **How it was discovered:** Not explicitly stated, but the attack was discovered and subsequently investigated by regulators leading to enforcement action.
- **Response actions taken:** Capita engaged with cyber authorities and regulators, took actions to improve its systems post-hack, and offered support to impacted individuals.
## Attack Methodology
- **Initial Access:** Exploitation of security weaknesses (Method not detailed).
- **Persistence:** Not detailed.
- **Privilege Escalation:** Not detailed.
- **Defense Evasion:** Not detailed.
- **Credential Access:** Not detailed.
- **Discovery:** Not detailed.
- **Lateral Movement:** Compromised multiple datasets affecting customers of organizations Capita supports.
- **Collection:** Gathered extensive personal data, including sensitive PII and Special Category Data.
- **Exfiltration:** Data concerning 6.6 million people was stolen.
- **Impact:** Significant regulatory penalty (£14 million) and extensive personal data exposure.
## Impact Assessment
- **Financial:** £14 million fine levied by the ICO. The initial proposed fine was £45 million, which was reduced based on subsequent remediation efforts.
- **Data Breach:** 6.6 million records exposed. Contained pension details, staff records, financial data, criminal records, and special category data (race, religion, sexual orientation).
- **Operational:** No specific quantification of operational downtime provided, though a major incident response was necessary.
- **Reputational:** Significant public reporting on the failure to protect customer and staff data leading to regulatory enforcement.
## Indicators of Compromise
- **Network indicators - defanged:** None provided.
- **File indicators:** None provided.
- **Behavioral indicators:** Unauthorized access and mass exfiltration of personal data.
## Response Actions
- **Containment measures:** Not detailed, but presumed to have been initiated upon discovery.
- **Eradication steps:** Capita took actions following the hack to "improve its systems."
- **Recovery actions:** Capita offered support to those impacted and engaged with regulatory authorities.
## Lessons Learned
- Capita failed to adequately protect the personal data it held, resulting in one of the largest fines imposed by the ICO in this context.
- The reliance on Capita as a subcontractor created a significant downstream risk for millions of individuals.
- A voluntary settlement allowed Capita to reduce its initial penalty (from £45M to £14M), indicating that proactive engagement post-breach can mitigate financial penalties.
## Recommendations
- Implement more robust security measures, especially focused on the protection and segmentation of highly sensitive data (e.g., special category data, criminal records).
- Thoroughly vet and continuously audit the security postures of all subcontractors handling sensitive personal data.
- Review incident response plans to ensure timely and comprehensive management of data exposure immediately following detection.