Lawyer sees almost 1,000 complainants sign up to Capita breach class action
- Reference: 1689935894
- News link: https://www.theregister.co.uk/2023/07/21/capita_breach_class_action/
- Source link:
Capita confirmed the burglary in [1]early April , saying at the time intruders had spent nine days on the inside before they were spotted. Some 0.1 percent of Capita servers were accessed and it had [2]evidence that data had been exfiltrated, including personal and corporate information.
In May, the tech services company [3]wrote to pension clients – it administers 450 schemes in Britain with 4.3 million members – to inform them that some of their data was housed in the systems that were potentially accessed. The Pension's Regulator advised clients to speak to Capita to ascertain the risk.
[4]
The Universities Superannuation Scheme (USS), Britain's largest private pension plan, [5]also warned its half a million members of the potential dangers, saying data on Capita's servers related to 470,000 active, deferred and retired members, and Capita had advised them to assume some data had been accessed or copied.
[6]
[7]
Step forward Barings Law, the Manchester-based solicitor that sent a [8]Letter of Claim to Capita in June to outline the case for its clients, which at that point totaled 250 individuals. This week the solicitor claims it has "signed up almost 1,000 clients."
A representative told us: "95 percent of Baring's clients relating to this are pension clients. The rest are former or current employees of Capita."
[9]
According to the USS, for example, the data accessed by Capita's intruders could include the pension member's titles, initials and name, date of birth, National Insurance number and USS member number.
[10]Capita staffers told attackers stole data from its own pension fund
[11]Capita wins £50M fraud reporting contract with City of London cops
[12]Another security calamity for Capita: An unsecured AWS bucket
[13]More UK councils caught by Capita's open AWS bucket blunder
Alex Mathewson, a 68-year-old retired miner from Barnsley, is among the individuals being represented by Barings Law. "When you've given nearly 50 years of blood, sweat and tears and then you're told something like this has happened, you feel let down," he said via a statement from the solicitor.
He is a member of the Mineworkers Pension Scheme, administered by Capita, which [14]wrote to customers last month to say their data might have been compromised in the breach, and to look out for fraud attempts.
No papers have yet been served to court by Barings Law, and Capita had three months to reply to the Letter of Claim sent weeks ago. The solicitor previously told us: "Capita may respond to say they are investigating this breach as due to the size and nature of the breach these investigations take time. The ICO will also be investigating (18-24 months for this to be finalised). Capita could wait for ICO to conclude their investigation before fully responding.
"If Barings Law issue to court at this stage and do not have a substantive response, the Judge may want to know why they did not wait before issuing in the high court. For this reason, it is common practice to wait before a firm issues in the high court. This could take 18-24 months from today."
[15]
Capita continues to investigate the breach with the help of external specialists, and reckons the [16]total cost of the clean-up will be in the region of £20 million , though analyst Megabuyte pointed out that reputational damage will be far greater.
The Information Commissioner's Office previously said around 90 organizations have reported breaches of personal data stored by Capita.
Capita declined to comment. ®
Get our [17]Tech Resources
[1] https://www.theregister.com/2023/04/03/capita_confirms_security_attack_as/
[2] https://www.theregister.com/2023/04/20/capita_admits_to_evidence_that/
[3] https://www.theregister.com/2023/05/05/capita_pension_data_breach/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZLqrprGGH111dap-7RB9DgAAA8A&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://www.theregister.com/2023/05/12/uks_largest_private_pension_scheme/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZLqrprGGH111dap-7RB9DgAAA8A&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZLqrprGGH111dap-7RB9DgAAA8A&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2023/06/16/capita_faces_first_legal_letter/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZLqrprGGH111dap-7RB9DgAAA8A&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2023/07/07/capita_pension_cyber_attack/
[11] https://www.theregister.com/2023/06/14/capita_city_of_london_fraud_reporting_service_contract/
[12] https://www.theregister.com/2023/05/17/another_security_calamity_for_capita/
[13] https://www.theregister.com/2023/05/22/capita_security_pensions_aws_bucket_city_councils/
[14] https://www.mps-pension.org.uk/news/2023/06/important-update-on-the-capita-cyber-incident
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZLqrprGGH111dap-7RB9DgAAA8A&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://www.theregister.com/2023/05/10/capita_breach_costs/
[17] https://whitepapers.theregister.com/
Re: Chernobyl
Maybe it’s time for them to flag a ride from Charon?
Not to mention that the general standards in the pension administration sector are dismal. I've had a lot of dealings over the past year with three large (non-Capita) pension administrators, and at every turn they've been slow, unhelpful, unresponsive, incompetent and denied obvious errors that are shown in black and white in their own records. In my entire life I've never come across a sector that seems so routinely poor and disinterested in the people it is there to serve.
I suspect the problem is that pension fund trustees rarely or never change their administrator, so its money for old rope, and there's no consequences for failure. In this case Capita will take a modest penalty from the ICO, but the corporate culture will remain unchanged.
@Lurka
"In my entire life I've never come across a sector that seems so routinely poor and disinterested in the people it is there to serve."
You never heard of Estate agents or Solicitors? And don't get me started on Politicians...
Wonder what percentage of each quid of compo (if any) the solicitors will take?
One day this is going to happen to Azure, AWS or Google Cloud.
I believe it's already happened to places like UKCloud and Rackspace.
I don't know why anyone would ever think that it wouldn't. But if we don't punish this one, then when it all goes wrong everyone will go "Oh, who knew?! Maybe we should do something about it for next time?". Capita need to be made an example off to try to head off an actual, proper, serious cloud breach.
Capita are well back in the queue of organisations waiting to be made an example of but so far it's not happened to any of them.
"Megabuyte pointed out that reputational damage [to Capita] will be far greater."
How? Capita couldn't damage their reputation any further if they changed their name to Hermes.
Or Chernobyl.