DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Why Capita Was Fined £14 Million for Failing to Secure Personal Data

The ICO’s £14 million penalty followed findings that Capita failed to prevent network movement, respond promptly to an alert and address security risks across its organization.
From TheFinanceBase Team3 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The UK Information Commissioner’s Office (ICO) fined Capita plc £8 million and its subsidiary Capita Pension Solutions Limited (CPSL) £6 million after finding that security weaknesses allowed attackers to steal data relating to 6,656,037 people in March 2023. The ICO said the companies failed to prevent unauthorised movement through Capita’s network and did not respond effectively to a high-priority alert. Both companies accepted the findings and agreed not to appeal as part of a voluntary settlement.

What happened in the March 2023 Capita cyberattack?

According to the ICO’s 15 October 2025 announcement and its monetary penalty notice, an employee unintentionally downloaded a malicious file on 22 March 2023. A high-priority alert was raised within ten minutes, but the device was not quarantined for 58 hours. The attacker used that foothold to install malicious software, gain administrator permissions and move into other parts of the network.

Nearly one terabyte of data was exfiltrated between 29 and 30 March. Ransomware was deployed on 31 March, when Capita became aware of the attack. The detailed notice and announcement place the incident in March 2023; a brief ICO enforcement listing labels it April, which conflicts with those records.

How much was each company fined?

Entity ICO-assessed role ICO findings Final penalty
Capita plc Data controller UK GDPR Articles 5(1)(f), 32(1) and 32(2) £8 million
Capita Pension Solutions Limited (CPSL) Data processor UK GDPR Articles 32(1) and 32(2) £6 million

The combined penalty was £14 million. The ICO had told Capita it intended to impose a provisional £45 million penalty; after considering the companies’ representations and mitigation, the final amount was reduced and settled voluntarily. The entities accepted the findings and agreed not to appeal. The ICO said each entity was responsible for its own compliance, even though the group used the same security measures.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What data and how many people were affected?

The monetary penalty notice gives the precise figure: data relating to 6,656,037 individuals was exfiltrated across the Capita Group. The ICO’s announcement rounded this to 6.6 million. The affected information included pension and staff records and information belonging to customers of organisations Capita supported. Some records contained financial information, criminal-record details or special-category personal data.

CPSL processed data for more than 600 organisations providing pension schemes; 325 of those organisations were also affected. The ICO reported at least 93 complaints about the incident. It said many people described anxiety and stress.

Why did the ICO find Capita’s security inadequate?

Weak controls over access and network movement

The ICO found that Capita lacked adequate controls to prevent privilege escalation and unauthorised lateral movement. It said vulnerabilities in these areas had been raised at least three times without being remedied. The notice treats the failure to prevent lateral movement and privilege escalation as running from 25 May 2018 to 31 March 2023.

A slow response to a high-priority alert

Although the alert was raised within ten minutes, the device took 58 hours to quarantine, against a one-hour response target. The ICO said the Security Operations Centre was understaffed and had fallen below target response times in at least six months before the attack. The notice sets the infringement period for ineffective security-alert response as 1 September 2022 to 31 March 2023.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Testing findings were not addressed across the organization

Systems holding millions of records, including sensitive information, were penetration-tested when commissioned but were not tested again afterward. According to the ICO, findings remained siloed within business units, so risks to the wider network were not handled consistently.

Is the credit-monitoring offer still available?

The ICO says Capita offered affected customers 12 months of credit monitoring through Experian and set up a dedicated call centre. More than 260,000 people activated the monitoring service. These are historical details from the enforcement decision; the ICO material does not establish that the offer remains available now. Anyone concerned about their own records should use contact details in communications from the relevant pension scheme or organisation, rather than assume they can still enrol in that offer.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What security lessons did the ICO draw?

The ICO’s lessons from the investigation are organizational safeguards, not a guarantee that any single measure can prevent an attack:

  • Apply least-privilege access and follow National Cyber Security Centre guidance to reduce opportunities for lateral movement.
  • Monitor for suspicious activity and respond to security alerts promptly, with staffing and escalation arrangements that support response targets.
  • Share penetration-test findings across the organization, then track whether identified risks are fixed and controls continue to work.
  • Review the division of security and data-protection responsibilities between controllers and processors.

In the ICO’s announcement, Information Commissioner John Edwards said: “Capita failed in its duty to protect the data entrusted to it by millions of people. The scale of this breach and its impact could have been prevented had sufficient security measures been in place.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.