News: 1683287849

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Capita admits some pension data 'likely' to have been accessed in March breach

(2023/05/05)


Capita is telling pension customers that some data contained within its systems was potentially accessed when criminals broke into the outsourcing giant's tech infrastructure earlier this year.

The business admitted to a "cyber incident" – that nebulous phrase which downplays the significance of an attack – in [1]March , when miscreants spent nine days inside the company's systems.

As part of the ongoing investigation, Capita said in April around [2]4 percent of its servers were accessed by the intruder and some customers, colleagues and suppliers' data was lifted. Russian extortionist crew [3]Black Basta claimed responsibility , saying it had floated some of the stolen data for sale, including Capita documents marked confidential, passport scans, bank account details and more.

[4]

Now it has emerged that the UK outsourcing giant, which has around £6.5 billion worth of contracts, has written to pension customers to confirm that data it processes for them may have been accessed, according to letters seen by the [5]Financial Times .

[6]

[7]

"To be clear, this does not necessarily mean that your data has been identified as exfiltrated, it means that your data was on [Capita] servers from which some data is likely to have been exfiltrated," the company said.

The probe Capita is going through, with help from forensic investigators, should be completed by the end of next week, the letter added. Capita also said it had not seen any pension data on the dark web and had a third-party specialist verifying this regularly. The server infrastructure was rebuilt to minimize the risk of a similar incident.

[8]

A spokesperson told us: "Capita is working closely with specialist advisors and forensic experts in investigating the incident to provide assurance around any potential customers, supplier or colleague data exfiltration.

[9]Criminal records office yanks web portal offline amid 'cyber security incident'

[10]Capita to see wave of UK government contracts come to an end by 2025

[11]UK Ministry of Defence takes recruitment system offline, confirms data leak

[12]Co-Operative Bank today 'terminated' Capita's outsourcing contract years before it was due to expire

"Capita continues to work through its forensic investigations and inform any customers, suppliers or colleagues that are impacted in a timely manner."

The London Stock Exchange-listed business administers more than 450 pension schemes with 4.3 million members. We do not know how many of these or which ones are affected, if any.

A legal specialist that works at a Capita pension client told the FT that trustees and managers are still "struggling" to "get data specific to their scheme's situation." Obviously they want to know whether their data was exposed and if it is now in criminal hands.

The Pensions Regulator (TPR) told us it is advising clients about the breach: "This is an ongoing situation with more detail emerging daily. We are in contact with trustees, other regulators and Capita. We have directed trustees to TPR and ICO [Information Commissioner's Office] guidance to help them in communicating with scheme members and we are speaking to Capita about what they are able to share with trustees.

[13]

"In light of the cyber incident directed at Capita, we have asked trustees of schemes which employ Capita as their administrator to speak with the company to understand more about the situation and to help determine whether there is a risk to their scheme's data.

"If a trustee establishes that their scheme has suffered a data loss, they have a duty to notify TPR, other authorities and impacted individuals. Our communication requires trustees to read TPR's and the ICO guidance on cyber and IT security and to make sure they are familiar with their responsibilities." ®

Get our [14]Tech Resources



[1] https://www.theregister.com/2023/04/03/capita_confirms_security_attack_as/

[2] https://www.theregister.com/2023/04/20/capita_admits_to_evidence_that/

[3] https://www.theregister.com/2023/04/18/capita_breach_gets_worse/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZFUoJplU-vWG-BXUSVrzKQAAANI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://www.ft.com/content/baa794ff-90dc-4d6c-a930-64dae7391940

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFUoJplU-vWG-BXUSVrzKQAAANI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFUoJplU-vWG-BXUSVrzKQAAANI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFUoJplU-vWG-BXUSVrzKQAAANI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2023/04/06/acro_security_incident/

[10] https://www.theregister.com/2022/05/31/capita_government_contracts_ending/

[11] https://www.theregister.com/2022/03/24/ministry_of_defence/

[12] https://www.theregister.com/2021/12/02/capitas_outsourcing_contract_with_cooperative/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFUoJplU-vWG-BXUSVrzKQAAANI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



Private Eye named them perfectly!

Plest

Once again Crapita prove that they're just a bunch of second-rate chancers run by bosses only interested in creaming in the profit of cushy, over-funded UK Gov projects. Come the glorious day citizens, Crapita's bosses will be first up against the wall!

Re: Private Eye named them perfectly!

Little Mouse

"they're just a bunch of second-rate chancers"

I disagree - They are very focused and good at what they do best, which is negotiate airtight contracts that guarantee a ridiculously good financial return for themselves, no matter how poorly they perform.

Re: Private Eye named them perfectly!

Lee D

Only "airtight" because some dumb head in politics who gets a back-hander knows that and signs them.

Nobody with purchasing responsibility and a brain would ever sign those kind of contracts, unless it was basically a back-hander large enough to guarantee their future, that would also absolve them of all responsibility.

Capita aren't some legal geniuses. The heads of organisations are basically being bribed into signing contracts that nobody in their right mind would ever sign, which tie in all their successors for decades in some cases.

I think it should be illegal in government to sign a deal that lasts longer than the next election, and even if you did, the courts should throw it out anyway.

Capita are very focused and good at what they do best

t245t

> Are very focused and good at what they do best, which is negotiate airtight contracts

And then outsource technical support to some budget data-center in India.

Cav

"The business admitted to a "cyber incident" – that nebulous phrase which downplays the significance of an attack"

No, it isn't. Until fully explained and investigated, it's an incident.

Keep ancient lands, your storied pomp! cries she
With silent lips. Give me your tired, your poor,
Your huddled masses yearning to breathe free,
The wretched refuse of your teeming shore.
Send these, the homeless, tempest-tossed to me...
-- Emma Lazarus, "The New Colossus"