Capita was fined for the data breach, which affected customers in 2023.

British outsourcing company Capita has been in the news after being fined £14m by the Information Commissioner's Office (ICO)for failing to protect the personal data of millions of citizens. The case relates to a massive cyberattack in March 2023, in which hackers stole the details of 6.6 million people, including pension information, personal employee and customer data.
The incident revealed security vulnerabilities in critical systems, as well as an inadequate real-time response. According to the ICO, Capita did not have the necessary technical and organizational measures in place to prevent or mitigate the impact of the attack.
See also: Hackers impersonate OpenAI and Sora to steal credentials
Double fine
The ICO fined Capita itself £8m and its subsidiary Capita Pension Solutions , which manages data for over 600 pension funds, £6m . Of these organisations, 325 were directly affected by the breach.
The breach included sensitive informationsuch as financial data, criminal records and personal data categories — from race and religion to sexual orientation. The ICO noted that this data “could have remained secure if Capita had implemented basic safeguards.”

How did the attack happen?
The cyberattack began on March 22, 2023, when an employee accidentally downloaded a malicious file. Although the system raised an alarm within 10 minutes, the company did not quarantine the infected device for 58 hours. During this delay, the hackers gained administrator rights, penetrated deeper into the network, and installed ransomware on March 31.The result: complete access blocking for employees and locking down critical systems.
According to the ICO, the response time for such cases should be one hour – a time frame that Capita dramatically exceeded. The incident is part of a wave of attacks in 2023, the same year that companies such as WH Smith and Royal Mail suffered serious cyberattacks.
See also: PolarEdge: New custom TLS Server backdoor
"Failure of duty" according to the Commissioner
The UK Information Commissioner, John Edwards, said: "Capita failed in its duty to protect the data entrusted to it by millions of people. This breach could have been avoided if adequate security measures had been taken."
The investigation concluded that the company had not provided for adequate detection and prevention mechanisms, while its crisis response protocols proved inadequate. Initially, the ICO intended to impose a fine of £45 million, but the amount was reduced due to Capita's cooperation and improvements to systems after the incident.
Capita's response and the new era of cybersecurity
The company issued a statement apologizing and confirming that all affected citizens had been notified. The new CEO, Adolfo Hernandez, who took over in 2024, stressed that Capita “experienced one of the first major attacks in the recent wave of cybercrime” and has since accelerated its digital transformation.
“We have significantly strengthened our cybersecurity posture, investing in advanced detection systems and embedding a culture of constant vigilance,” Hernandez said.
See also: Invoicely: Over 178,000 customer data files exposed
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The company had estimated that the total cost of the attack, including recovery costs, expert fees and new security investments, could reach £25 million, not including fines.
Lessons for the future: From reaction to prevention
The Capita case is a significant warning for organizations handling large volumes of personal data. The key lessons are clear:
- Speed of response to breach incidents is critical.
- Businesses should implement multi-layered protection, from staff training to automated threat isolation systems.
- And, above all, the cybersecurity culture must permeate every level of the company, from the frontline worker to management.
As 2025 marks a new surge in cyberattacks on large European businesses, the Capita case is a reminder that even market giants can be brought to their knees if security is not a priority.
