Desk live·
ForensicPost
Ransomware/Third party/File 23-0331

Capita Took 58 Hours to Quarantine the Device That Started Its Breach

A malicious file reached an employee device on 22 March and an alert fired within ten minutes. The device was not isolated for more than two days, and by 31 March the attacker had deployed ransomware across a thousand hosts and reset every account on the system.

Constructed geometry · not a chart of case data
JurisdictionUnited Kingdomthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCapita
ActorBlack Basta
S. Rosler12 min readConfidence: high3 sources reviewed

The UK Information Commissioner’s Office fined Capita £14 million over a 2023 breach affecting more than six million people. Its account of the timeline is the reason this file exists in the form it does.

A malicious file was downloaded onto an employee device on 22 March 2023. A high-priority security alert was raised within ten minutes and some automated action followed. The device was not quarantined for 58 hours.

The Detection Worked

This is not a file about a control that failed to fire. The alert existed, it was correctly classified as high priority, and it arrived inside ten minutes — better than almost any dwell figure in this database.

What failed was the distance between an alert and an action. The corpus argues at 25-1207 and 26-0303 that detection without an owner authorised to act is a log entry, and this is the clearest instance it holds: 58 hours of a known-bad device on the network, with the finding already made.

What Nine Days Bought The Attacker

On 31 March the attacker deployed ransomware to over a thousand hosts and reset the passwords of all 59,359 accounts on the system. Capita interrupted the incident the same day.

Personal information of around 6.6 million people was taken, spanning pension records, staff records and the customers of organisations Capita administers on behalf of others. For some individuals this included special category data.

An Outsourcer Holds Other People’s Populations

Capita administers hundreds of pension schemes covering millions of memberships. None of those members chose Capita, and most would not have been able to name it.

This is the corpus’s most persistent finding, filed at 26-0731 for Conduent, at 25-1219b for a supplier serving two thousand practices, and at 26-0628 for a state licensing vendor. The organisation with the relationship and the organisation with the data are different organisations, and only one of them is regulated as if it holds it.

How we reported this

Built on the ICO’s published enforcement notice and on the Pensions Regulator’s regulatory intervention report, both retrieved and read by this desk. The 22 March download, the ten-minute alert, the 58-hour quarantine delay, the 31 March ransomware deployment, the 59,359 account resets and the 6.6 million affected are the regulators’ own findings. The attribution to Black Basta is as reported by Computer Weekly, which also reported Capita writing to pension trustees on 4 May 2023; it is not a regulator finding. The £14 million penalty was issued in 2025 and is recorded here because it is the source of the timeline, not because it falls in 2023. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Capita fined £14m for data breach affecting over 6m peopleInformation Commissioner’s Office
  2. Capita cyber security incident — regulatory intervention reportThe Pensions Regulator
  3. Capita pension clients told data may have leakedComputer Weekly
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary