The UK Information Commissioner’s Office (ICO) fined Capita plc £8 million and its subsidiary Capita Pension Solutions Limited (CPSL) £6 million after finding that security weaknesses allowed attackers to steal data relating to 6,656,037 people in March 2023. The ICO said the companies failed to prevent unauthorised movement through Capita’s network and did not respond effectively to a high-priority alert. Both companies accepted the findings and agreed not to appeal as part of a voluntary settlement.
What happened in the March 2023 Capita cyberattack?
According to the ICO’s 15 October 2025 announcement and its monetary penalty notice, an employee unintentionally downloaded a malicious file on 22 March 2023. A high-priority alert was raised within ten minutes, but the device was not quarantined for 58 hours. The attacker used that foothold to install malicious software, gain administrator permissions and move into other parts of the network.
Nearly one terabyte of data was exfiltrated between 29 and 30 March. Ransomware was deployed on 31 March, when Capita became aware of the attack. The detailed notice and announcement place the incident in March 2023; a brief ICO enforcement listing labels it April, which conflicts with those records.
How much was each company fined?
| Entity | ICO-assessed role | ICO findings | Final penalty |
|---|---|---|---|
| Capita plc | Data controller | UK GDPR Articles 5(1)(f), 32(1) and 32(2) | £8 million |
| Capita Pension Solutions Limited (CPSL) | Data processor | UK GDPR Articles 32(1) and 32(2) | £6 million |
The combined penalty was £14 million. The ICO had told Capita it intended to impose a provisional £45 million penalty; after considering the companies’ representations and mitigation, the final amount was reduced and settled voluntarily. The entities accepted the findings and agreed not to appeal. The ICO said each entity was responsible for its own compliance, even though the group used the same security measures.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
What data and how many people were affected?
The monetary penalty notice gives the precise figure: data relating to 6,656,037 individuals was exfiltrated across the Capita Group. The ICO’s announcement rounded this to 6.6 million. The affected information included pension and staff records and information belonging to customers of organisations Capita supported. Some records contained financial information, criminal-record details or special-category personal data.
CPSL processed data for more than 600 organisations providing pension schemes; 325 of those organisations were also affected. The ICO reported at least 93 complaints about the incident. It said many people described anxiety and stress.
Why did the ICO find Capita’s security inadequate?
Weak controls over access and network movement
The ICO found that Capita lacked adequate controls to prevent privilege escalation and unauthorised lateral movement. It said vulnerabilities in these areas had been raised at least three times without being remedied. The notice treats the failure to prevent lateral movement and privilege escalation as running from 25 May 2018 to 31 March 2023.
A slow response to a high-priority alert
Although the alert was raised within ten minutes, the device took 58 hours to quarantine, against a one-hour response target. The ICO said the Security Operations Centre was understaffed and had fallen below target response times in at least six months before the attack. The notice sets the infringement period for ineffective security-alert response as 1 September 2022 to 31 March 2023.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Testing findings were not addressed across the organization
Systems holding millions of records, including sensitive information, were penetration-tested when commissioned but were not tested again afterward. According to the ICO, findings remained siloed within business units, so risks to the wider network were not handled consistently.
Is the credit-monitoring offer still available?
The ICO says Capita offered affected customers 12 months of credit monitoring through Experian and set up a dedicated call centre. More than 260,000 people activated the monitoring service. These are historical details from the enforcement decision; the ICO material does not establish that the offer remains available now. Anyone concerned about their own records should use contact details in communications from the relevant pension scheme or organisation, rather than assume they can still enrol in that offer.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What security lessons did the ICO draw?
The ICO’s lessons from the investigation are organizational safeguards, not a guarantee that any single measure can prevent an attack:
- Apply least-privilege access and follow National Cyber Security Centre guidance to reduce opportunities for lateral movement.
- Monitor for suspicious activity and respond to security alerts promptly, with staffing and escalation arrangements that support response targets.
- Share penetration-test findings across the organization, then track whether identified risks are fixed and controls continue to work.
- Review the division of security and data-protection responsibilities between controllers and processors.
In the ICO’s announcement, Information Commissioner John Edwards said: “Capita failed in its duty to protect the data entrusted to it by millions of people. The scale of this breach and its impact could have been prevented had sufficient security measures been in place.”
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteQuick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




