News: 1683910754

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Britain's largest private pension scheme reveals scale of Capita break-in

(2023/05/12)


Universities Superannuation Scheme, the UK’s largest private pension provider, says Capita has warned that details of almost half a million members were held on servers accessed during the recent breach.

The USS made the disclosure today, saying that it uses Capita technology platform, Hartlink, to manage in-house pension administration processes, and was working closely with the scandal struck Capita since the digital burglary in March.

Layoff-happy Capita charges staff to use cutlery in canteens [1]READ MORE

“While it has been confirmed that USS member data held on Hartlink has not been compromised, we were informed on Thursday 11 May that regrettably details of USS members were held on the Capita servers accessed by the hackers,” USS [2]said on its website today .

The data potentially accessed includes title, initials and name, date of birth, National Insurance number and US member number. It dates from early 2021 and covers "around 470,000 active, deferred and retired members."

“While Capita cannot currently confirm if this data was definitively 'exfiltrated' (ie, accessed and/or copied) by the hackers, they recommend we work on the assumption it was,” the USS adds in a statement on its website today.

[3]

USS says it is waiting for Capita to send over specific data that it will need to check and process. “We will be writing to each of the members affected by this – and, where applicable, their employers – as soon as possible to make them aware, to apologise for any distress or inconvenience caused, and to provide ongoing support and advice.”

[4]

[5]

Crooks broke into Capita’s IT infrastructure in March and weren’t spotted by the tech services biz for nine days until March 31, when it was forced to [6]shut down systems to contain any spread of infection. In early April, Capita confirmed it was dealing with a " [7]cyber incident ," and has since issued updates but has yet to confirm what type of security nasty it was trying to mitigate.

Russian ransomware crew [8]Black Basta has claimed responsibility , saying it had put up for sale sensitive documents including passport details, bank account information and more. Capita has kept quiet on the culprit but initially said 4 percent of its servers were accessed and it had [9]evidence data was exfiltrated .

[10]

Last week, Capita - which administers 450 pensions in the UK with 4.3 million members - [11]wrote to pensions customers warning that servers accessed may have contained their data. This week, Capita told investors the cost of cleaning up the breach would run to [12]£20 million ($25.24 million).

Capita also claimed that “some data was exfiltrated from less than 0.1 percent” of its server estate, though the nature of that data could be highly sensitive.

[13]British govt tech supplier Capita crippled by 'IT issue'

[14]Capita: Cyber-attack broke some of our IT systems

[15]Capita IT breach gets worse as Black Basta claims it's now selling off stolen data

[16]Capita has 'evidence' customer data was stolen in digital burglary

[17]Capita admits some pension data 'likely' to have been accessed in March breach

[18]Capita admits some pension data 'likely' to have been accessed in March breach

[19]Capita looking at a bill of £20M over breach clean-up costs

In a statement sent to The Register , a Capita spokesperson said: “Capita continues to work closely with specialist advisers and forensic experts to investigate the incident and we have taken extensive steps to recover and secure the data.

“In line with our previous announcement, we are now informing those we have identified to be affected. We have worked quickly to provide our clients with information, reassurance and support, while delivering for them as a business. In instances where we need to provide further support to those affected, we will do so.”

We asked The Pension’s Regulator to comment. Last week it told us this was an ongoing and developing situation with fresh details emerging daily.

[20]

The cost of the clean-up effort is one aspect for Capita, but as analyst Megabuyte noted this week: “reputational damage for a key supplier to critical UK government services such as Capita is likely far greater.” ®

Get our [21]Tech Resources



[1] https://www.theregister.com/2015/06/26/capita_charges_cutlery_canteens/

[2] https://www.uss.co.uk/news-and-views/latest-news/2023/05/05122023_important-information-about-capitas-cyber-incident

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZF63CuyxKiIFcbMOzVhDFQAAAAk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZF63CuyxKiIFcbMOzVhDFQAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZF63CuyxKiIFcbMOzVhDFQAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/03/31/capita_confirms_it_outage/

[7] https://www.theregister.com/2023/04/03/capita_confirms_security_attack_as/

[8] https://www.theregister.com/2023/04/18/capita_breach_gets_worse/

[9] https://www.theregister.com/2023/04/20/capita_admits_to_evidence_that/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZF63CuyxKiIFcbMOzVhDFQAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2023/05/05/capita_pension_data_breach/

[12] https://www.theregister.com/2023/05/10/capita_breach_costs/

[13] https://www.theregister.com/2023/03/31/capita_confirms_it_outage/

[14] https://www.theregister.com/2023/04/03/capita_confirms_security_attack_as/

[15] https://www.theregister.com/2023/04/18/capita_breach_gets_worse/

[16] https://www.theregister.com/2023/04/20/capita_admits_to_evidence_that/

[17] https://www.theregister.com/2023/05/05/capita_pension_data_breach/

[18] https://www.theregister.com/2023/05/05/capita_pension_data_breach/

[19] https://www.theregister.com/2023/05/10/capita_breach_costs/

[20] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZF63CuyxKiIFcbMOzVhDFQAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[21] https://whitepapers.theregister.com/



I will believe it when...

VoiceOfTruth

-> “reputational damage for a key supplier to critical UK government services such as Capita is likely far greater.”

A contract that was outsourced to Capita is cancelled on those grounds. Or, when some large public body rejects a tender from Capita on those grounds. Or, when HM government, in general, rejects Capita from bidding with those ground stated for disqualification.

Three options. My tarot cards offer no such prediction.

Re: I will believe it when...

Yet Another Anonymous coward

You forget it's binary.

Every time they fsckup the "don't deal with these idiots again" bit is flipped, and the next time they fsckup the bit is cleared.

Here...

steviebuk

...you are Crapita. We've seen your recent break in but here's another multi million pound government contract. Cause we're too fucking lazy to do a new tender process cause we know we'll just pick you anyway. Yours Clueless UK Gov.

Re: Here...

Anonymous Coward

Tender process:

Q1. To avoid the risk of your company failing to be able to deliver this contract, do your annual revenues meet or exceed Crapitas?

Q2. Are you an existing supplier and can therefore skip any competence tests?

Q3. Are you willing to provide the lowest cost bid, knowing that you can more than make up for it with scope changes

Q4. Do you have multiple board members who make generous donations to political parties? Bonus points for supporting multiple parties to avoid being caught out by pesky elections.

Q5. Do you have and easy to hate PR spokespeople that can be wheeled out in front of the public to divert attention for any failures on the part of the government, the bureaucracy or you company?

Please submit your tender documents in envelopes large enough to support your tender submission and enough Bank of England padding to ensure the submission is not damaged in transit.

Please...

IGotOut

Get the 10% of annual turnover off these clowns.

Oh I forgot, the government will pay them £20billion to set up the excel spreadsheet required to collect it.

Nifty

"National Insurance number and US member number". Now I'm confused as to how these 2 items are in the same database.

anothercynic

Because those running USS are idiots?

Doctor Syntax

Let me hazard a guess ast to how "US" gets expanded in this instance: "Universities' Superannuation".

Can't wait...

anothercynic

... For the information about this. No doubt the UCU union will have an absolute field day given that this pension fund holds the pensions of every lecturer and every member of staff of every classic uni (and many research orgs) in the country. Well done, Crapita, well done. I guess the next evaluation will be lower still to hide the fact that this happened instead of recovering any damages from Capita, and all that'll be offered will be a year's fraud monitoring.

I know what "custody" [of the children] means. "Get even." That's all
custody means. Get even with your old lady.
-- Lenny Bruce