News: 1681997354

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Capita has 'evidence' customer data was stolen in digital burglary

(2023/04/20)


Business process outsourcing and tech services player Capita says there is proof that some customer data was scooped up by cyber baddies that broke into its systems late last month.

The British listed business, which has around £6.5 billion ($8.09 billion) in public sector contracts, [1]updated the London Stock Exchange this morning to confirm the criminals breached its infrastructure on March 22 and remained inside until “interrupted” by the company on March 31.

“As a result of the interruption, the incident was significantly restricted, potentially affecting around 4 percent of Capita’s server estate. There is currently some evidence of limited data exfiltration from the small proportion of affected server estate which might include customer, supplier or colleague data.”

[2]

“Capita continues to work through its forensic investigations and will inform any customers, suppliers or colleagues that are impacted in a timely manner,” it said, adding: “Capita continues to comply with all relevant regulatory obligations.”

[3]

[4]

This comes after Russian extortionist crew [5]Black Basta claimed it was behind the digital burglary at Capita and put up for sale sensitive information it reckons it stole, and which reportedly includes personal bank account details of people and business selling products or services to Capita. This is supposedly just small snippets of the data for sale.

Infosec veteran Kevin Beaumont previously said the stolen information being offered for sale also included a Capita Nuclear document - Capita provides support staff for the command centre of the Civil Nuclear Constabulary - paper marked confidential, and the floor plans of multiple buildings.

[6]

Beaumont said earlier this month: “Capita's customers and regulators should be asking Capita to explain this – on the record and in writing.”

[7]Capita to see wave of UK government contracts come to an end by 2025

[8]UK Ministry of Defence takes recruitment system offline, confirms data leak

[9]Capita scores half a billion pound outsourcing contract, but refuses to name (or shame?) lucky 'European telco' customer

[10]Shuttered call centre sours Capita's £58m contract extension with Tesco Mobile

[11]Just let this sink in: Capita wins 12-year £1bn contract to provide training services to the Royal Navy and Marines

[12]Millions wiped off value of Capita outsourcing deal with English councils amid 'further contract variation agreement'

[13]Transport for London asks Capita to fling Congestion Charge system into the cloud

[14]Gulp! Irish Water outsources contact centres to Capita for up to €27m over 7 years

"Failing to disclose the loss of personal data can have serious financial and reputation damages — in short, do not cover up ransomware and extortion incidents or you may end up the case history of how not to respond," he added.

Capita opened up on IT systems issues at the end of March, when its Azure Directory or Azure Active Director Service was [15]suddenly unavailable to its own employees, impacting access to Microsoft 365 applications.

Days later [16]Capita confirmed a “cyber incident” had disrupted services internally.

TechMartketViews analyst Marc Hardwick said the “million dollar questions” that are now facing Capita are “what data has been accessed, and to what extent the impact can be mitigated and how quickly this can be done.”

[17]

The Information Commissioner’s Office, the UK’s data watchdog, reiterated an earlier comment: "Capita has reported an incident to us and we are making enquiries." ®

Get our [18]Tech Resources



[1] https://www.londonstockexchange.com/news-article/CPI/statement-re-update-on-cyber-incident/15923779

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZEFhoqg8JChjewQ@u6-fPgAAAEM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZEFhoqg8JChjewQ@u6-fPgAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZEFhoqg8JChjewQ@u6-fPgAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2023/04/18/capita_breach_gets_worse/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZEFhoqg8JChjewQ@u6-fPgAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/05/31/capita_government_contracts_ending/

[8] https://www.theregister.com/2022/03/24/ministry_of_defence/

[9] https://www.theregister.com/2021/06/15/capita_europe_telco_deal/

[10] https://www.theregister.com/2021/06/11/capita_58m_tesco_mobile_extension/

[11] https://www.theregister.com/2020/12/18/capita_navy_training/

[12] https://www.theregister.com/2020/11/23/capita_oxfordshire_councils_deal/

[13] https://www.theregister.com/2020/08/10/transport_for_london_capita_contract/

[14] https://www.theregister.com/2020/06/16/capita_irish_water_contract/

[15] https://www.theregister.com/2023/03/31/capita_confirms_it_outage/

[16] https://www.theregister.com/2023/04/03/capita_confirms_security_attack_as/

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZEFhoqg8JChjewQ@u6-fPgAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[18] https://whitepapers.theregister.com/



"... potentially affecting around 4 percent of Capita’s server estate ..."

John H Woods

Just the storage (DB, file and object) servers then?

Re: "... potentially affecting around 4 percent of Capita’s server estate ..."

Little Mouse

Or, maybe, damn near ALL the servers for specific contracts? I wonder which ones?

Back in the day, C-word contracts were typically siloed from each other, separated from pretty much everything except the mothership (I don't know if anything's changed since things went all cloudy...) It certainly made things nice and simple when it was time to wind a contract down and they decided to do a bit of pruning. Snip! And you're all gone.

Re: "... potentially affecting around 4 percent of Capita’s server estate ..."

Captain Scarlet

Depends on whether the businesses they have brought and ruined in the process were fully integrated or not (Normally I find this when they demand payment and forget to tell us whichever company they brought that we used has had finances assimiliated).

Crapita stop buying and then ruining companies we use!

Crapita

Grooke

Have we stopped using the correct name for them?

Sigh

tiggity

The longer this drags on the more it confirms how crap Crapita are.

Be honest and open early instead of being shifty and evasive*

Even just admitting a breach ASAP (once reasonable mitigations in place to stop further breach progress / exfiltration obviously) and say that more details will be coming later will be seen as fine: Unless they have an appalling setup & staff it should not have taken a huge amount of time to detect & stop the breach.

As the article mentions infosec folk such as Kevin (AKA Gossi the dog), worth noting that the Crapita breach has been talked about on various infosec forums for quite a while and Crapita were glacial in confirming the breach given it was "common knowledge" they were victims.

* Even if you take massive precautions you cannot guarantee you are "safe", if you are a decent sized company worth having a "when, not if we get hacked" mindset as there's always the chance of a zero day (or the soft option of staff revealing credentials be it via phishing , more old school social engineering, hacks of staff machine via staff home network (with WFH if someone breaks into a home network always worth their while finding out who the mark(s) work for as can make a nice juicy attack vector into the company they work for ) etc.).

Typically with exfiltration of data you have a decent time window to detect things (as once the attackers are in its worth their while seeing how far they can spread in case they can find higher value targets as often entry point will not hold "crown jewels" level of data ) and so there are key things to look out for e.g. in addition to looking out for unusual internal network activity also check unusual outgoing network activity (as files are shipped out) ). Always an arms race detecting nasty data egress, made more painful these days by the like of CDNs and cloudy services. Typically can be a bit of a pain to easily tell if some data going to Cloudflare, AWS is legit CDN or cloud use or whether its an attacker as they often grab data multi-step via "innocuous" looking initial pathways (as mentioned the likes of Cloudflare, AWS etc will usually have plenty of valid connections made from a corporate network so a sensible initial exfiltration connection point) rather than slurping it directly to more suspect looking IPs they control.

I'm very happy I no longer have anything to do with the security side of things** in current job (as, when I was more involved in that side of things in other roles you always felt disaster was just around the corner & every CVE made your sphincter tighten in case it was something that could leave you wide open).

** Obv, still make an effort on home networks security side of things but that's not got any particularly sensitive / valuable data (if someone gets in they won't find NI number, phone number, DOB, lists of passwords etc. on any of my personal machines) unlike commercial "work" data security scenarios.

It's not like Crapita process any important data to do with the UK's national security...

Anonymous Coward

Just the recruitment process for anyone applying to join the British Army.

As said, nothing important. {facepalm}.

"By long-standing tradition, I take this opportunity to savage other
designers in the thin disguise of good, clean fun."
-- P. J. Plauger, from his April Fool's column in April 88's
"Computer Language"