The UK Information Commissioner’s Office fined Capita £14 million over a 2023 breach affecting more than six million people. Its account of the timeline is the reason this file exists in the form it does.
A malicious file was downloaded onto an employee device on 22 March 2023. A high-priority security alert was raised within ten minutes and some automated action followed. The device was not quarantined for 58 hours.
The Detection Worked
This is not a file about a control that failed to fire. The alert existed, it was correctly classified as high priority, and it arrived inside ten minutes — better than almost any dwell figure in this database.
What failed was the distance between an alert and an action. The corpus argues at 25-1207 and 26-0303 that detection without an owner authorised to act is a log entry, and this is the clearest instance it holds: 58 hours of a known-bad device on the network, with the finding already made.
What Nine Days Bought The Attacker
On 31 March the attacker deployed ransomware to over a thousand hosts and reset the passwords of all 59,359 accounts on the system. Capita interrupted the incident the same day.
Personal information of around 6.6 million people was taken, spanning pension records, staff records and the customers of organisations Capita administers on behalf of others. For some individuals this included special category data.
An Outsourcer Holds Other People’s Populations
Capita administers hundreds of pension schemes covering millions of memberships. None of those members chose Capita, and most would not have been able to name it.
This is the corpus’s most persistent finding, filed at 26-0731 for Conduent, at 25-1219b for a supplier serving two thousand practices, and at 26-0628 for a state licensing vendor. The organisation with the relationship and the organisation with the data are different organisations, and only one of them is regulated as if it holds it.
Built on the ICO’s published enforcement notice and on the Pensions Regulator’s regulatory intervention report, both retrieved and read by this desk. The 22 March download, the ten-minute alert, the 58-hour quarantine delay, the 31 March ransomware deployment, the 59,359 account resets and the 6.6 million affected are the regulators’ own findings. The attribution to Black Basta is as reported by Computer Weekly, which also reported Capita writing to pension trustees on 4 May 2023; it is not a regulator finding. The £14 million penalty was issued in 2025 and is recorded here because it is the source of the timeline, not because it falls in 2023. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.
- Capita fined £14m for data breach affecting over 6m peopleInformation Commissioner’s Office
- Capita cyber security incident — regulatory intervention reportThe Pensions Regulator
- Capita pension clients told data may have leakedComputer Weekly