ICO fines Capita £14m for March 2023 data breach
The Information Commissioner’s Office (ICO) has fined Capita plc £8m and Capita Pension Solutions Limited £6m, totalling £14m, for failing to ensure the security of personal data following a cyber attack in March 2023. The breach resulted in hackers stealing information belonging to approximately 6.6 million individuals, including pension records, staff data, and sensitive financial and criminal information. The ICO found that Capita failed to ensure the secure processing of personal data, leaving its systems at risk, and had not implemented adequate technical and organisational measures to effectively prevent or respond to the attack.