News: 1680300513

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

British govt tech supplier Capita crippled by 'IT issue'

(2023/04/01)


Capita, a major business and IT services provider that has scored multi-million-dollar contracts with several UK government agencies, confirmed some of its systems fell over today due to "an IT issue."

Staff at the London-based giant couldn't access their own work email, their Microsoft cloud accounts, and other systems beginning Friday morning. The biz issued a [1]statement on Twitter, and promised more information would be forthcoming.

"Following a technical problem which has affected access to some of our services today, we can confirm that we have identified an IT issue that is primarily impacting our internal systems," the technology outsourcer said.

[2]

"The reality is that we've had no access to anything related to Capita's Azure Directory (AD) or Azure Active Directory, which includes VPN and all Microsoft 365 and Azure services," a Register -reading Capita insider told us.

[3]

[4]

"The company is essentially at a standstill although I'm guessing that they're gathering forensic data prior to restoring AD. There are rumors of an offshore employee clicking on a JavaScript-infected email, but that is exactly that. Rumor and conjecture. No one outside of the Red Team has any real knowledge - which is probably how it should be."

Can you shed more light on Capita's woes? Drop us [5]a line in confidence.

Capita provides a huge number of services for Blighty's [6]National Health Service organizations , as well as the British Army, Royal Navy, and fire and rescue operations for the [7]Ministry of Defence , among other public and private organizations, including O2.

The company's public-sector contracts total £6.5 billion ($8.2 billion), [8]according to The Guardian . And because its contracted services are so enmeshed with those provided by the British government, the outage sparked concerns about disruptions to critical health and emergency services, as well as a possible nation state cyberattack.

The [9]Financial Times , citing "people familiar with the matter," said the outage affected Microsoft 365 applications, including Office email and video conferencing. Companies such as O2 that use Capita's call centers also reported broken-down systems and processing delays stemming from the IT snafu.

[10]

An unnamed Capita employee told The Guardian they were unable to log into their laptop after their password was rejected as "incorrect."

Additionally, a text message sent to all staff read: "We are urgently investigating this and will provide you with an update shortly. Please do not attempt to access via VPN or submit password recovery requests."

[11]UK Ministry of Defence takes recruitment system offline, confirms data leak

[12]What's the price of failure? For Capita, it's a £140m extension to its MoD recruiting contract

[13]Psst! Infosec bigwigs: Wanna be head of security at HM Treasury for £50k?

[14]NHS Highland 'reprimanded' by data watchdog for BCC blunder with HIV patients

At press time, the UK Cabinet Office did not respond to The Register 's specific inquiries, though issued an earlier media statement saying, "We are aware of an incident affecting some systems within Capita and we are in regular contact with the company as they continue to investigate the issue."

This latest IT meltdown at Capita comes a year after the UK Ministry of Defence suspended its online application and support services for the British Army's [15]Crapita-run recruitment system after tech issues.

The army was alerted to the behind-the-scenes gremlins, and "that a group of hackers was going to release Army Application Data on the dark web," a source familiar with the matter told The Register at the time. ®

Get our [16]Tech Resources



[1] https://twitter.com/CapitaPlc/status/1641818647340490752

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZCesXtezsVQamdKCJ1CJNgAAANM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCesXtezsVQamdKCJ1CJNgAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCesXtezsVQamdKCJ1CJNgAAANM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/Author/Email/encrypted-message-desk

[6] https://capitahealthcaredecisions.com/solutions/nhs/#:~:text=Our%20Solutions%20for%20NHS%20Organisations&text=Telephone%2Dbased%20patient%20assessment%20is,pressure%20on%20public%20healthcare%20systems.

[7] https://www.capita.com/expertise/industry-specific-services/defence

[8] https://www.theguardian.com/business/2023/mar/31/capita-it-systems-fail-cyber-attack-nhs-fears

[9] https://www.ft.com/content/00f9591f-e07a-4339-ba3e-413818602515

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCesXtezsVQamdKCJ1CJNgAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2022/03/24/ministry_of_defence/

[12] https://www.theregister.com/2020/12/14/capita_recruiting_partnership_project_140m_extension/

[13] https://www.theregister.com/2023/03/31/job_ad_hm_treasury/

[14] https://www.theregister.com/2023/03/31/nhs_highland_reprimanded_by_data/

[15] https://www.theregister.com/2022/03/24/ministry_of_defence/

[16] https://whitepapers.theregister.com/



No doubt more negligent Microsoft shite

Anonymous Coward

Somebody sue them for all their assets.

Anonymous Coward

Did someone forget to update some certificates? or was it a targeted Russian attack to find out our secret trade deals that will allow us to sell cheese to Asia?

sanmigueelbeer

Somewhat related ... [1]Revealed: How Hackers Used DXC to Get Inside Australian Fintech, Latitude Financial

[1] https://www.afr.com/technology/revealed-how-hackers-used-a-tech-giant-to-get-inside-latitude-financial-20230323-p5cukr

that nickname?

Bebu

Had never heard of Capita so was thinking "knee capper" as in "you'll never walk again" but I noticed later in the article crapita which probably better as in "you're up to your neck in it." Where the "you" as always, is the poor customer.

/*
* Oops. The kernel tried to access some bad page. We'll have to
* terminate things with extreme prejudice.
*/
die_if_kernel("Oops", regs, error_code);
(From linux/arch/i386/mm/fault.c)