What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Capita confirmed in April 2023 that attackers had stolen some data after the ransomware group Black Basta listed the company on its leak site and offered information for sale. The offer was reported at the time; the available sources do not establish that a sale was completed. Later findings from the UK Information Commissioner’s Office (ICO), announced in October 2025, put the incident’s scale at personal information relating to 6.6 million people and a combined £14 million penalty.
What happened in the Capita data breach?
The incident began with an employee inadvertently downloading a malicious file, according to the ICO’s later investigation. Attackers then moved through Capita’s systems, extracted data, and deployed ransomware. The sequence below reflects the ICO’s account, alongside Capita’s and contemporaneous reporting where noted.
- 22 March 2023: A malicious file was downloaded to an employee device. A high-priority security alert was raised within ten minutes, but the device was not quarantined for 58 hours. The ICO’s account says the response target was one hour.
- 29–30 March: The attacker exfiltrated nearly one terabyte of data, according to the ICO.
- 31 March: Ransomware was deployed and user passwords were reset, disrupting staff access. Capita became aware of the cyber incident that day.
- 3 April: Capita said some client pension services were disrupted and that it had isolated and contained the issue. The Pensions Regulator later said pension payments were not interrupted, although some administrative services were affected. The regulator’s account covers the pension impact.
- 8 April: Black Basta listed Capita on its leak site and shared files as evidence of exfiltration. SecurityWeek reported that the group offered information for sale. The report does not establish that a sale took place.
- 20 April: Capita confirmed data theft, saying the intrusion began around 22 March and was interrupted on 31 March, with evidence of limited data exfiltration, as reported by SecurityWeek.
What information was stolen, and how many people were affected?
The ICO said personal information was stolen from pension records, staff records, and customers of organisations Capita supports. Depending on the individual, the information could include criminal-record details, financial data, or special-category data. The types and extent of exposure were not the same for everyone.
The ICO’s 2025 public summary says the incident involved personal information relating to 6.6 million people. Its penalty notice gives a more exact figure of 6,656,037 impacted personal-data records; records are not necessarily unique people. The notice also says approximately 974.84 GB was understood to have been exfiltrated from data affected by encryption. That total volume was not necessarily all personal data. The ICO penalty notice explains the distinction.
#1 Best Overall
The ICO says 325 pension-scheme client organisations were affected. Capita Pension Solutions processed personal information for more than 600 organisations providing pension schemes, according to the ICO; that wider figure is not the number of affected clients. Separately, the Pensions Regulator said Capita supported more than 450 pension schemes and approximately 4.3 million memberships. Those membership figures do not mean that every member was affected by the breach.
Why do early reports give a different estimate?
Early reporting put the potentially affected infrastructure at around 4% of Capita’s server estate. Capita later revised that estimate to less than 0.1%. These percentages describe the share of servers, not the share of people affected or the amount of data stolen. They therefore do not contradict the ICO’s later finding about millions of people’s personal information. SecurityWeek reported the change in Capita’s estimate.
What did the ICO find, and what was the penalty?
On 15 October 2025, the ICO announced a final combined penalty of £14 million: £8 million for Capita plc and £6 million for Capita Pension Solutions Limited. The ICO said the companies accepted a voluntary settlement, admitted liability, and agreed not to appeal. The initial proposed total had been £45 million. The ICO’s announcement sets out the outcome.
The ICO identified shortcomings involving administrative-account tiering and privilege escalation, movement between domains, response to security alerts, and penetration testing and risk assessment. It said relevant weaknesses had been identified before the incident but not remedied. The regulator also found that a high-priority alert was raised within ten minutes, yet an appropriate response took 58 hours against a one-hour target. These are the ICO’s findings, not an independent technical assessment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.“Capita failed in its duty to protect the data entrusted to it by millions of people. The scale of this breach and its impact could have been prevented had sufficient security measures been in place.”
John Edwards, UK Information Commissioner, 15 October 2025
What should you do if you may have been affected?
Public incident totals cannot show whether a particular person’s records were involved or which files were accessed. Contact the pension scheme, employer, or other organisation that holds your information and follow its official communications. Trustees were urged by the Pensions Regulator to tell members promptly when there was a reasonable chance their data was at risk, without waiting for investigations to finish.
The ICO says Capita offered affected customers 12 months of credit monitoring through Experian and set up a dedicated call centre; more than 260,000 people activated the service. This was a historical offer recorded by the ICO and does not establish that the service remains available now.
Best Value
What organisations can learn from the incident
The ICO’s findings point to practical areas for organisations to review:
Quick Recap
- Limit administrative privileges and separate administrative accounts into appropriate tiers.
- Set clear response targets for high-priority alerts, and ensure devices can be isolated promptly when needed.
- Use regular penetration testing and risk assessments to identify weaknesses before an attacker does.
- Share security findings across the organisation and track remediation to completion.
- Make controller and processor responsibilities clear, including who communicates with affected people.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

