Capita class action: 2,000 folks affected by data theft sign up
- Reference: 1694599339
- News link: https://www.theregister.co.uk/2023/09/13/capita_class_action_2000_claimants/
- Source link:
Manchester-based Barings Law dispatched a legal [1]Letter of Claim to Capita concerning the breach in June after claiming it received a “staggering number” of enquiries, and by July said it had [2]1,000 clients on board . Code block text
In the latest update, the lawyer claims that figure has doubled to 2,000 - comprised of pension customers, employees and circa 100 individuals that operate in the medical profession. It believes millions of people's personal information including passport details, emails and home addresses could have been revealed to criminals in the breach.
"Barings Law are still receiving a large number of enquiries and sign ups on a daily basis," claimed Adnan Malik, head of data breach at the lawyer.
Capita took down its IT systems at the end of March after spotting that an intruder had broken through its tech defenses. The break-in happened on March 22 and wasn't spotted until March 31 when Capita interrupted them.
[3]
Russian ransomware crew [4]Black Basta claimed responsibility for the criminal act, and posted data, including bank account information, addresses and passport photos they to have accessed.
[5]
[6]
Capita initially thought 4 percent of its server estate were accessed but later revised this to 0.1 percent, and admitted there was [7]some evidence that customer, supplier or colleague data had been seen by the criminals.
Pension data was also added to the list the following month in [8]May as investigators combed over the wreckage – Capita administers 450 pension schemes that contain 4.3 million members. The Pensions Regulator was notified and was advising its clients speak to Capita directly about any risks.
[9]
Britain's largest pension scheme, the [10]Universities Superannuation Scheme also told members their data might have been accessed, and Capita warned staff that its [11]own pension fund was among the victims of the March burglary.
UK data watchdog, the Information Commissioner's Office reckoned that as of May, 90 companies had informed them that their information had been breached in the Capita burglary.
The cost of the clean-up effort is estimated by Capita to be close to £25 million, the company said when releasing its financial results last month, which is 25 percent higher than [12]previous estimate .
[13]Another security calamity for Capita: An unsecured AWS bucket
[14]Capita wins £50M fraud reporting contract with City of London cops
[15]More UK councils caught by Capita's open AWS bucket blunder
[16]Activists gatecrash Capita's AGM to protest GPS tracking contract
In a statement to The Register , a Capita spokesperson said: "Capita treats cyber security with the utmost seriousness and, in common with many organisations, regularly reviews its cyber security stance using third-party consultants where appropriate."
"The company has invested in a multi-year, multi-million-pound cyber security programme which has been accelerated in the wake of March's cyber incident.
[17]
"Capita has since been praised by external experts for its high level of cyber preparedness, and both UK government and commercial clients have expressed their gratitude over its handling of the incident."
"Capita strongly rejects any suggestion that there is any valid basis for bringing claims against it as a result of the cyber incident."
We asked the company how the investigation into the incident is progressing and when it will have further information to share with the public, but it refused to say more at this stage. ®
Get our [18]Tech Resources
[1] https://www.theregister.com/2023/06/16/capita_faces_first_legal_letter/
[2] https://www.theregister.com/2023/07/21/capita_breach_class_action/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZQHcpTrihatoY9uoqYXgywAAAss&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2023/04/18/capita_breach_gets_worse/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZQHcpTrihatoY9uoqYXgywAAAss&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZQHcpTrihatoY9uoqYXgywAAAss&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2023/04/20/capita_admits_to_evidence_that/
[8] https://www.theregister.com/2023/05/05/capita_pension_data_breach/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZQHcpTrihatoY9uoqYXgywAAAss&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2023/05/12/uks_largest_private_pension_scheme/
[11] https://www.theregister.com/2023/07/07/capita_pension_cyber_attack/
[12] https://www.theregister.com/2023/05/10/capita_breach_costs/
[13] https://www.theregister.com/2023/05/17/another_security_calamity_for_capita/
[14] https://www.theregister.com/2023/06/14/capita_city_of_london_fraud_reporting_service_contract/
[15] https://www.theregister.com/2023/05/22/capita_security_pensions_aws_bucket_city_councils/
[16] https://www.theregister.com/2023/05/12/activists_gatecrash_capitas_agm_to/
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZQHcpTrihatoY9uoqYXgywAAAss&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[18] https://whitepapers.theregister.com/
In other news.
My B.H. just got an email from Freecycle saying that they have had account information stolen and to change their password; even though the passwords were hashed.
I however haven’t.
Odd.
Er - not very good reporting
"Class action" is a distinctly American concept that doesn't really translate to the UK. We have "Group Litigation Orders" - which the article should have made clear.
https://www.emmlegal.com/publications/class-actions/
"Capita strongly rejects any suggestion that there is any valid basis for bringing claims against it as a result of the cyber incident."
Rice-Divies applies
"Capita strongly rejects any suggestion that there is any valid basis for bringing claims against it as a result of the cyber incident."
- You promised to securely store personal data.
- That personal data was illegally accessed and stolen.
That sounds like a pretty solid valid basis to me - It's about time companies like this stopped taking all the profits, and passing on all the liabilities.
How do I know if my details where exposed?
How do we know if our data has been exposed?
Has my TV licence info been accessed.
My pensions, nobody is giving us the info, so we can't sue them.