HomeSecurityCapita: £14 million fine for 2023 data breach

Capita: £14m fine for 2023 data breach

Capita was fined for the data breach, which affected customers in 2023.

Capita Data Breach Fine

British outsourcing company Capita has been in the news after being fined £14m by the Information Commissioner's Office (ICO)for failing to protect the personal data of millions of citizens. The case relates to a massive cyberattack in March 2023, in which hackers stole the details of 6.6 million people, including pension information, personal employee and customer data.

The incident revealed security vulnerabilities in critical systems, as well as an inadequate real-time response. According to the ICO, Capita did not have the necessary technical and organizational measures in place to prevent or mitigate the impact of the attack.

See also: Hackers impersonate OpenAI and Sora to steal credentials

Double fine

The ICO fined Capita itself £8m and its subsidiary Capita Pension Solutions , which manages data for over 600 pension funds, £6m . Of these organisations, 325 were directly affected by the breach.

The breach included sensitive informationsuch as financial data, criminal records and personal data categories — from race and religion to sexual orientation. The ICO noted that this data “could have remained secure if Capita had implemented basic safeguards.”

Capita: £14m fine for 2023 data breach

How did the attack happen?

The cyberattack began on March 22, 2023, when an employee accidentally downloaded a malicious file. Although the system raised an alarm within 10 minutes, the company did not quarantine the infected device for 58 hours. During this delay, the hackers gained administrator rights, penetrated deeper into the network, and installed ransomware on March 31.The result: complete access blocking for employees and locking down critical systems.

According to the ICO, the response time for such cases should be one hour – a time frame that Capita dramatically exceeded. The incident is part of a wave of attacks in 2023, the same year that companies such as WH Smith and Royal Mail suffered serious cyberattacks.

See also: PolarEdge: New custom TLS Server backdoor

"Failure of duty" according to the Commissioner

The UK Information Commissioner, John Edwards, said: "Capita failed in its duty to protect the data entrusted to it by millions of people. This breach could have been avoided if adequate security measures had been taken."

The investigation concluded that the company had not provided for adequate detection and prevention mechanisms, while its crisis response protocols proved inadequate. Initially, the ICO intended to impose a fine of £45 million, but the amount was reduced due to Capita's cooperation and improvements to systems after the incident.

Capita's response and the new era of cybersecurity

The company issued a statement apologizing and confirming that all affected citizens had been notified. The new CEO, Adolfo Hernandez, who took over in 2024, stressed that Capita “experienced one of the first major attacks in the recent wave of cybercrime” and has since accelerated its digital transformation.

“We have significantly strengthened our cybersecurity posture, investing in advanced detection systems and embedding a culture of constant vigilance,” Hernandez said.

See also: Invoicely: Over 178,000 customer data files exposed

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Capita: £14m fine for 2023 data breach

The company had estimated that the total cost of the attack, including recovery costs, expert fees and new security investments, could reach £25 million, not including fines.

Lessons for the future: From reaction to prevention

The Capita case is a significant warning for organizations handling large volumes of personal data. The key lessons are clear:

  • Speed ​​of response to breach incidents is critical.
  • Businesses should implement multi-layered protection, from staff training to automated threat isolation systems.
  • And, above all, the cybersecurity culture must permeate every level of the company, from the frontline worker to management.

As 2025 marks a new surge in cyberattacks on large European businesses, the Capita case is a reminder that even market giants can be brought to their knees if security is not a priority.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS