Capita fined £14m for data protection failings in 2023 cyber-attack

A picture


The outsourcing company Capita has been fined £14m for data protection failings after hackers stole the personal information of 6,6 million people, including staff details and those of its clients’ customers,John Edwards, the UK information commissioner who levied the fine, said the March 2023 data theft from the group and companies it supported, including 325 pension providers, caused anxiety and stress for those affected,The £8m fine for Capita and £6m penalty for its Capita Pension Solutions arm come as UK businesses battle a wave of cyber-attacks in the recent wave that has crippled companies such as M&S and Jaguar Land Rover,Capita discovered the attack within 10 minutes but did not shut down the device that had been targeted by a malicious file for 58 hours, during which time the attacker was able to exploit its systems.

Hackers took almost one terabyte of data, installed ransomware and reset all user passwords, locking out Capita staff,In some cases stolen information was sensitive, such as details of criminal records, financial data and “special category data”, which can include race, religion and sexual orientation,An original proposed fine of £45m was cut after Capita made representations it had made security improvements and engaged with regulators and the National Cyber Security Centre, part of GCHQ, which this week said the number of nationally significant cyber-attacks in the UK more than doubled in the past year,It called on businesses of all sizes to draw up contingency plans for if “your IT infrastructure [is] crippled tomorrow and all your screens [go] blank”,The information commissioner’s investigation found that prior to the attack, Capita failed to fix known vulnerabilities, its security operations centre was understaffed and it had carried out inadequate testing of defences despite looking after millions of personal and sometimes sensitive records.

“Capita failed in its duty to protect the data entrusted to it by millions of people,” Edwards said.“The scale of this breach and its impact could have been prevented had sufficient security measures been in place.“When a company of Capita’s size falls short, the consequences can be significant.Not only for those whose data is compromised – many of whom have told us of the anxiety and stress they have suffered – but for wider trust among the public and for our future prosperity.As our fine shows, no organisation is too big to ignore its responsibilities.

”Sign up to Business TodayGet set for the working day – we'll point you to all the business news and analysis you need every morningafter newsletter promotionCapita’s chief executive, Adolfo Hernandez, said: “As an organisation delivering essential public services as well as key services for private sector clients, Capita was among the first in the recent wave of highly significant cyber-attacks on large UK companies.“When I joined as CEO the year after the attack I accelerated our cyber security transformation, with new digital and technology leadership and significant investment.As a result, we have hugely strengthened our cybersecurity posture, built in advanced protections and embedded a culture of continuous vigilance.”
sportSee all
A picture

England v Pakistan: Women’s Cricket World Cup match abandoned due to rain – as it happened

Raf’s report is here – goodnight!I think we showed that we can beat England, but [the rain] was not in our favour.[On her four-for with the ball] I know this pitch has been good for the fast bowlers so I just tried to bowl a good length. It would have been good [to take those wickets] if we had won the match.We've bowled well in the last couple of matches so hopefully we can improve our bowling in the next few games.I thought Pakistan bowled brilliantly and made it really hard for us to get into the game at all

A picture

India to host 2030 Commonwealth Games – next stop the 2036 Olympics?

India will be formally approved as hosts of the centenary Commonwealth Games in 2030 next month as the country steps up its ambitions to stage the 2036 Olympics.Commonwealth Sport says its executive board had recommended Ahmedabad, in the state of Gujarat, as the host city for the 2030 Games ahead of what it called an “ambitious bid” by Nigeria. The decision still needs to be ratified by a general assembly in Glasgow on 26 November, but multiple sources described that process a formality.The Commonwealth Sport chief executive, Katie Sadleir, said: “Today’s recommendation is strategically important for the future of the Commonwealth Sport movement. It builds on the platform that Glasgow 2026 will provide and sets a clear direction for the years ahead

A picture

Aisle pay that: seat surcharges leave spectators on edge at some of Australia’s biggest events

Some fans hate being stepped over inside the stadium and just want to enjoy the action in peace. Others won’t sit anywhere else except the end of a row, and are prepared to pay a premium for the privilege.The extra cost of an aisle seat has reached $25 at the Melbourne Formula One Grand Prix, as part of a trend adopted at sporting events such as the MotoGP at Phillip Island and the Australian Open tennis, as well as at some music concerts, to price tickets on the edge of bays higher than those in the middle.A spokesperson for Tennis Australia confirmed aisle seat pricing was first introduced at the Melbourne Park major in 2022, with a “modest premium” of $5, “responding to fan preferences for extra legroom and easier access”.The Australian Open is placing a premium of between $5 and $15 on aisle seats for the 2026 tournament, although not all bays in all sessions carry the extra charge

A picture

Ryder Cup triumph being remembered for the wrong reasons, says Rory McIlroy

Rory McIlroy is eager to shift discussion of last month’s Ryder Cup from the dominant theme of unruly spectators to the “incredible” strength of Europe’s display.Luke Donald and his European team secured back-to-back Ryder Cup wins after reaching what ultimately proved an unassailable position within two of the event’s three days.The reference point for Bethpage Black, though, has been appalling fan conduct; including significantly towards McIlroy. The Masters champion’s wife was hit by a beer thrown from the galleries at one point, with McIlroy himself subjected to abuse throughout.McIlroy’s return to the competitive fold, this week at the India Championship, has led him to try to change the topic of conversation

A picture

George Russell stays at Mercedes next season but door not shut on pursuit of Verstappen

George Russell will remain with Mercedes for next season after the Formula One team confirmed they would be sticking with their drivers in 2026. However, the length of the contracts signed by the Briton and his teammate, Kimi Antonelli, have not been specified, potentially leaving the Formula One team open to once more pursue Red Bull’s Max Verstappen for 2027.The long-expected decision comes after a protracted period of negotiation with Russell, as Mercedes seek stability going into the new regulations of 2026. The 27-year-old British driver has five wins in eight seasons in F1, including victory in Singapore, helping propel Mercedes into a fight for second in the world championship with Ferrari and Red Bull.Russell, who came up through the Mercedes junior programme, is fourth in the world championship

A picture

George Ford turns down R360 riches for last shot at England World Cup glory

George Ford has turned down the riches on offer from R360 for one last shot at a Rugby World Cup with England. The 32-year-old revealed he was approached by the rebel circuit, fronted by the former England centre Mike Tindall, but rejected a deal believed to be worth £1m a season to chase his dream.Ford, who reached a century of caps last summer, has signed a three-year contract extension with Sale which will ensure his availability for the 2027 World Cup in Australia.“As players, we understand what’s going on with trying to set up this new league and they did contact my agent to have discussions,” Ford said.“My decision-making was purely based on the fact that I love playing for England and I’ve got an unbelievable desire to keep playing for England