News: 1683716450

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Capita looking at a bill of £20M over breach clean-up costs

(2023/05/10)


Britain's leaky outsourcing behemoth Capita is warning investors that the clean-up bill for its recent digital break-in will cost up to £20 million ($25.24 million).

At the end of March, the business was blindsided when criminals broke into its tech infrastructure and stayed inside for more than a week before Capita realized it was the victim of a "cyber incident."

The company [1]shut down its systems , pulling access to a range of Microsoft applications, as it tried to [2]head off the attacker/s.

[3]

Russian ransomware extortionists subsequently [4]claimed responsibility . External help was hired with forensic investigators combing through the systems to ascertain what happened. Capita said in April that [5]4 percent of its servers were accessed by the intruder/s and there was evidence some data was stolen.

[6]

[7]

In a [8]statement to the London Stock Exchange this morning , Capita said work with specialist advisors – the National Cyber Security Centre is helping out – and security experts was ongoing and the total expense is becoming clearer.

"Capita expects to incur exceptional costs of approximately £15m to £20m associated with the cyber incident, comprising specialist professional fees, recovery and remediation costs and investment to reinforce Capita's cyber security environment," the company said.

[9]UK Ministry of Defence takes recruitment system offline, confirms data leak

[10]A right Royal pain in the Dallas: City IT systems crippled by ransomware

[11]IT giant Bitmarck shuts down customer, internal systems after cyberattack

[12]Criminal records office yanks web portal offline amid 'cyber security incident'

Unsurprisingly, the tech service biz has "also taken steps to ensure the integrity, safety and security of its IT infrastructure to underpin its ongoing clients service commitments." The high-profile breach will not have been music to the ears of its customer base.

Capita has around £6.5 billion ($8 billion) worth of public and private sector contracts, including with various departments of UK government.

[13]

In today's update, it now believes that "some data was exfiltrated from less than 0.1 percent of its server estate. Capita has taken extensive steps to recover and secure the customer, supplier and colleagues data contained within the impacted server estate, and to remediate any issues arising from the incident."

This, of course, could be 0.1 percent of "most sensitive" data, as analysts at Megabyte rightly pointed out in response.

It emerged last week that Capita had written to pension clients – it administers 450 pension schemes with 4.3 million members – to say that their data [14]might have been lifted from its systems . We do not know how many, if any, are actually affected.

[15]

Capita said it is working with "all appropriate regulatory authorities and with customers, suppliers and colleagues to notify those affected and take any remaining necessary steps to address the incident."

James Preece, analyst at Megabyte, said the situation at Capita developed from an i"nitial cyber breach that restricted internal access to a few Office applications into a full-on customer and supplier data exfiltration clanger."

He said £20 million is "no small drop in the ocean, but the reputational damage for a key supplier to critical UK government services such as Capita is likely far greater."

The "debacle" underlines the "importance of a good cyber posture and the cost of getting it wrong," he added. Security researcher Kevin Beaumont has repeatedly pulled Capita across hot coals for what he sees as a [16]lack of transparency in the way it has dealt with the breach. ®

Get our [17]Tech Resources



[1] https://www.theregister.com/2023/03/31/capita_confirms_it_outage/

[2] https://www.theregister.com/2023/04/03/capita_confirms_security_attack_as/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZFu-pvRE6oh7lcZ-iBn0mgAAAJQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.theregister.com/2023/04/18/capita_breach_gets_worse/

[5] https://www.theregister.com/2023/04/20/capita_admits_to_evidence_that/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFu-pvRE6oh7lcZ-iBn0mgAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFu-pvRE6oh7lcZ-iBn0mgAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.londonstockexchange.com/news-article/CPI/update-on-actions-taken-to-resolve-the-cyber-incident/15949544

[9] https://www.theregister.com/2022/03/24/ministry_of_defence/

[10] https://www.theregister.com/2023/05/05/dallas_royal_ransomeare/

[11] https://www.theregister.com/2023/05/01/bitmarck_data_breach/

[12] https://www.theregister.com/2023/04/06/acro_security_incident/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFu-pvRE6oh7lcZ-iBn0mgAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/2023/05/05/capita_pension_data_breach/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFu-pvRE6oh7lcZ-iBn0mgAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://doublepulsar.com/russian-hackers-exfiltrated-data-from-capita-over-a-week-before-outage-b67453e0bd59

[17] https://whitepapers.theregister.com/



Are they kidding?

msknight

"but reputational damage could be 'far greater'" ... what reputation? Who wrote that?

Re: Are they kidding?

Peter Christy

That's why they are universally known as "Crapita", isn't it?

Capita has taken extensive steps to recover ... the data

Anonymous Coward

Would love to know how. Surely a nobel prize must be in the office for "recovering" the data.

Because I can't see how the miscreants still don't have it. Were they sent a stiff letter ?

Let's make it clear.

Anonymous Coward

There's no such thing as reputation damage. Worst case scenario, they will continue to do business as usual under a different name. And governments will be pleased to do business with them.

Already the spirit of our schooling is permeated with the feeling that
every subject, every topic, every fact, every professed truth must be
submitted to a certain publicity and impartiality. All proffered
samples of learning must go to the same assay-room and be subjected to
common tests. It is the essence of all dogmatic faiths to hold that
any such "show-down" is sacrilegious and perverse. The characteristic
of religion, from their point of view, is that it is intellectually
secret, not public; peculiarly revealed, not generally known;
authoritatively declared, not communicated and tested in ordinary
ways...It is pertinent to point out that, as long as religion is
conceived as it is now by the great majority of professed religionists,
there is something self-contradictory in speaking of education in
religion in the same sense in which we speak of education in topics
where the method of free inquiry has made its way. The "religious"
would be the last to be willing that either the history of the
content of religion should be taught in this spirit; while those
to whom the scientific standpoint is not merely a technical device,
but is the embodiment of the integrity of mind, must protest against
its being taught in any other spirit.
-- John Dewey (1859-1953), American philosopher,
from "Democracy in the Schools", 1908