---
title: What can we learn from the Capita data breaches?
description: Capita’s cyber security practices should be second to none. Yet recent events have illustrated how supply chain security cannot be taken for granted. Find out more...
image: https://blog.grantmcgregor.co.uk/hubfs/data%20breach.png
---

<https://grantmcgregor.co.uk/>

<https://grantmcgregor.co.uk/>[![Grant McGregor](https://blog.grantmcgregor.co.uk/hubfs/GRMC_blue_logo.svg "Grant McGregor")](https://www.grantmcgregor.co.uk/)

- [Home](https://grantmcgregor.co.uk/)
- About Us

    - [Our Story](https://grantmcgregor.co.uk/about-us/our-story)
    - [Meet the Team](https://grantmcgregor.co.uk/about-us/meet-the-team)
    - [Certifications](https://grantmcgregor.co.uk/about-us/certifications)
    - [Careers](https://grantmcgregor.co.uk/about-us/careers)
- IT Support Services

    - [IT Support Services](https://grantmcgregor.co.uk/it-support-services)
    - [People Centric Support](https://grantmcgregor.co.uk/it-support-services/people-centric-support)
    - [Enhanced Security Service](https://grantmcgregor.co.uk/it-support-services/enhanced-security-service)
- Professional IT Services

    - [Professional IT Services](https://grantmcgregor.co.uk/professional-it-services)
    - [Microsoft 365](https://grantmcgregor.co.uk/professional-it-services/microsoft-365-business-premium)
    - [Microsoft Copilot](https://grantmcgregor.co.uk/professional-it-services/microsoft-365-copilot)
    - [AI Adoption Services](https://grantmcgregor.co.uk/ai-adoption-services)
    - [Microsoft Azure](https://grantmcgregor.co.uk/professional-it-services/microsoft-azure)
    - [MDR](https://blog.grantmcgregor.co.uk/mdr-vs-soc-cyber-security-defence)
    - [Microsoft Teams Phone](https://grantmcgregor.co.uk/professional-it-services/microsoft-teams-phone)
    - [KnowBe4](https://grantmcgregor.co.uk/professional-it-services/knowbe4)
    - [DMARC](https://grantmcgregor.co.uk/professional-it-services/dmarc)
    - [Enclave Networks](https://grantmcgregor.co.uk/professional-it-services/enclave-networks)
- [Cyber Security](https://grantmcgregor.co.uk/cyber-security)
- Knowledge Hub

    - [Case Studies](https://grantmcgregor.co.uk/knowledge-hub/case-studies)
    - [Testimonials](https://grantmcgregor.co.uk/knowledge-hub/success-stories)
    - [Blog](https://grantmcgregor.co.uk/knowledge-hub/blog)
    - [Podcast](https://grantmcgregor.co.uk/knowledge-hub/podcast)
- [Client Area](https://grantmcgregor.co.uk/client-area)
- [Contact us](https://grantmcgregor.co.uk/contact-us)

- [Home](https://grantmcgregor.co.uk/)
- About Us

    - [Our Story](https://grantmcgregor.co.uk/about-us/our-story)
    - [Meet the Team](https://grantmcgregor.co.uk/about-us/meet-the-team)
    - [Certifications](https://grantmcgregor.co.uk/about-us/certifications)
    - [Careers](https://grantmcgregor.co.uk/about-us/careers)
- IT Support Services

    - [IT Support Services](https://grantmcgregor.co.uk/it-support-services)
    - [People Centric Support](https://grantmcgregor.co.uk/it-support-services/people-centric-support)
    - [Enhanced Security Service](https://grantmcgregor.co.uk/it-support-services/enhanced-security-service)
- Professional IT Services

    - [Professional IT Services](https://grantmcgregor.co.uk/professional-it-services)
    - [Microsoft 365](https://grantmcgregor.co.uk/professional-it-services/microsoft-365-business-premium)
    - [Microsoft Copilot](https://grantmcgregor.co.uk/professional-it-services/microsoft-365-copilot)
    - [AI Adoption Services](https://grantmcgregor.co.uk/ai-adoption-services)
    - [Microsoft Azure](https://grantmcgregor.co.uk/professional-it-services/microsoft-azure)
    - [MDR](https://blog.grantmcgregor.co.uk/mdr-vs-soc-cyber-security-defence)
    - [Microsoft Teams Phone](https://grantmcgregor.co.uk/professional-it-services/microsoft-teams-phone)
    - [KnowBe4](https://grantmcgregor.co.uk/professional-it-services/knowbe4)
    - [DMARC](https://grantmcgregor.co.uk/professional-it-services/dmarc)
    - [Enclave Networks](https://grantmcgregor.co.uk/professional-it-services/enclave-networks)
- [Cyber Security](https://grantmcgregor.co.uk/cyber-security)
- Knowledge Hub

    - [Case Studies](https://grantmcgregor.co.uk/knowledge-hub/case-studies)
    - [Testimonials](https://grantmcgregor.co.uk/knowledge-hub/success-stories)
    - [Blog](https://grantmcgregor.co.uk/knowledge-hub/blog)
    - [Podcast](https://grantmcgregor.co.uk/knowledge-hub/podcast)
- [Client Area](https://grantmcgregor.co.uk/client-area)
- [Contact us](https://grantmcgregor.co.uk/contact-us)

[Contact Us](https://grantmcgregor.co.uk/contact-us)

[Back to main](https://grantmcgregor.co.uk/knowledge-hub/blog)

Cyber Security

# What can we learn from the Capita data breaches?

Grant McGregor Team

 7 June 2023 • 6 min read

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.grantmcgregor.co.uk%2Fwhat-can-we-learn-from-the-capita-data-breaches> <https://x.com/intent/tweet?url=https%3A%2F%2Fblog.grantmcgregor.co.uk%2Fwhat-can-we-learn-from-the-capita-data-breaches&text=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EWhat+can+we+learn+from+the+Capita+data+breaches%3F%3C%2Fspan%3E&via=yourusername> <https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.grantmcgregor.co.uk%2Fwhat-can-we-learn-from-the-capita-data-breaches&title=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EWhat+can+we+learn+from+the+Capita+data+breaches%3F%3C%2Fspan%3E>

![](https://blog.grantmcgregor.co.uk/hubfs/data%20breach.png)

## As one of the UK’s leading providers of business process outsourcing services, Capita’s cyber security practices should be second to none. Yet the events of this year have strikingly illustrated how supply chain security cannot be taken for granted.

 

So, what can organisations learn from the data breaches at Capita?

On March 31, the business outsourcing company Capita announced that some of its staff were experiencing problems and outages with essential systems. It raised immediate concern because of the company’s client list, which includes local and central government institutions as well as major UK companies.

### A muted response to the incident

However, the response was muted – largely because Capita chose to downplay the incident, informing customers that there was no cause for concern. The company’s initial statement said, “The issue was limited to parts of the Capita network and there is no evidence of customer, supplier or colleague data having been compromised.”

It wasn’t until [April 20](https://www.theguardian.com/business/2023/apr/20/capita-admits-customer-data-may-have-been-breached-during-cyber-attack) that Capita finally announced that the incident was likely a result of a malicious hacking attack.

Subsequent evidence and analysis suggest that Capita most likely knew this was the case at the time of its original announcement and that the initial breach occurred on March 22. Indeed, as early as April 8, the ransomware group Black Basta was sharing leaked Capita data on its website.

### Why did Capita choose to downplay the incident?

Capita’s sluggishness in coming forward with information and its decision to downplay the incident in its early stages seem incomprehensible, given the services it provides and its customer base.

The UK GDPR requires organisations to report data breaches to the Information Commissioner Office (ICO) within 72 hours of them being uncovered. Significant fines and penalties apply if this reporting isn’t made.

The breach and the failure to adequately report it are a significant dint to Capita’s reputation. Furthermore, Capita’s lacklustre response has focused a great deal of attention on the company’s data security and cyber security practices.

### Bad practices come to light

In May, the news broke of a further data security problem at Capita. The vulnerability was reported to Capita by [a security researcher](https://www.computerweekly.com/news/366536736/Capita-pension-clients-told-data-may-have-leaked) who had been looking into the original cyber-attack. In a problem that is thought to date back to 2016, a misconfigured AWS S3 storage bucket had no password protection, leaving the files stored there unsecured. Kevin Beaumont alerted Capita to the issue in April but the news was only released in May.

The delay in reporting this second issue further compounds the damage to Capita’s reputation. How can its customers trust it to tell them when their data and their customers’ data has been compromised?

### The downstream effects of the Capita breach

Since April, more than 90 organisations have reported data breaches to ICO as a result of the Capita breach. These organisations include a number of [local councils](https://www.publictechnology.net/articles/news/%E2%80%98extremely-concerned-and-disappointed%E2%80%99-%E2%80%93-more-councils-caught-capita-breach) as well as [household names](https://www.computerweekly.com/news/366537238/Black-Basta-ransomware-attack-to-cost-Capita-over-15m) including Marks & Spencer, Diageo and Royal Mail.

The [pensions regulator](https://www.thepensionsregulator.gov.uk/en/document-library/statements/capita-cyber-security-incident) wrote to more than 300 pensions funds to ask them to check whether data had been stolen. It reminded them “As trustees you are responsible for the security of your members’ data. If you use Capita’s services, you should check whether your pension scheme’s data could be affected. Make sure you keep communicating with Capita as the situation evolves.”

However, security experts have warned that it could be years before the full extent of the data breach comes to light. Meanwhile, [the Register](https://www.theregister.com/2023/04/18/capita_breach_gets_worse/) has reported that Black Basta is selling sensitive exfiltrated data, including bank account information, addresses, and passport photos stolen from the IT outsourcing giant.

### NCSC calls for more transparency around attacks

Eleanor Fairford, deputy director of incident management at the UK’s[National Cyber Security Centre (NCSC)](https://www.ncsc.gov.uk/blog-post/why-more-transparency-around-cyber-attacks-is-a-good-thing-for-everyone), is increasingly concerned about the number of attacks that are not reported and pass quietly by, pushed aside, with ransoms paid swiftly to make the problem go away.

“The NCSC supports victims of cyber incidents every day, but we are increasingly concerned about the organisations that decide not to come forward,” she said. “Keeping a cyber-attack secret helps nobody except the perpetrators, so we strongly encourage victims to report incidents and seek support to help effectively deal with the fallout. By responding openly and sharing information, organisations can help mitigate the risk to their operations and reputation, as well as break the cycle of crime to prevent others from falling victim.”

### Learning from the Capita experience

Capita expects to incur “exceptional costs” in the region of £15m to £20m as a result of the March 2023 Black Basta ransomware attack on its systems, according to [Computer Weekly](https://www.computerweekly.com/news/366537238/Black-Basta-ransomware-attack-to-cost-Capita-over-15m).

Getting ahead of the news and reporting the data breach early to ICO would have helped to minimise any costs associated with ICO penalties, which have yet to be announced. 

Although Capita is working with security experts now, to understand the breach and close further vulnerabilities, doing this work upfront would not only have been better, it may well also have been more cost effective.

### Actions your organisation can take now

If you’ve been affected by the Capita breach, then the NCSC advice is to stay in contact with the company. Any breaches of personal data should be [reported to ICO](https://blog.grantmcgregor.co.uk/what-does-brexit-mean-for-gdpr) immediately.

The Capita breach has demonstrated the knock-on effects of data breaches very clearly. It’s a really good idea to understand how and where your organisation’s and your customers’ data is being shared. Begin by following the NCSC’s advice on [mapping your supply chain](https://blog.grantmcgregor.co.uk/is-your-organisation-doing-enough-on-supply-chain-security).

ICO has also emphasised the need to follow basic cyber security good practice. Not password protecting an exposed S3 bucket of customer data was a clear failure on Capita’s part. It reveals that even some of the biggest IT outsourcers can fail to follow basic levels of security. The [Cyber Essentials framework](https://blog.grantmcgregor.co.uk/new-changes-to-cyber-essentials-for-2023) is a great place to start to ensure that your organisation has basic, essential measures in place.

### What next?

If you’d like personalised advice about how your organisation can respond to the Capita breach, or would like advice on cyber security generally, please contact our team.

Call us: 0808 164 4142

Message us: [https://www.grantmcgregor.co.uk/contact-us](https://www.grantmcgregor.co.uk/contact-us)

Further reading

Find more information about cyber security topics on our blog:

•    [AI’s new role in cyber security](https://blog.grantmcgregor.co.uk/ais-new-role-in-cyber-security)

•    [Is your organisation doing enough on supply chain security?](https://blog.grantmcgregor.co.uk/is-your-organisation-doing-enough-on-supply-chain-security)

•    [New changes to Cyber Essentials for 2023](https://blog.grantmcgregor.co.uk/new-changes-to-cyber-essentials-for-2023)

•    [How to minimise the risk from phishing](https://blog.grantmcgregor.co.uk/how-to-minimise-the-risk-from-phishing)

Grant McGregor Team

 7 June 2023 • 6 min read

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.grantmcgregor.co.uk%2Fwhat-can-we-learn-from-the-capita-data-breaches> <https://x.com/intent/tweet?url=https%3A%2F%2Fblog.grantmcgregor.co.uk%2Fwhat-can-we-learn-from-the-capita-data-breaches&text=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EWhat+can+we+learn+from+the+Capita+data+breaches%3F%3C%2Fspan%3E&via=yourusername> <https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.grantmcgregor.co.uk%2Fwhat-can-we-learn-from-the-capita-data-breaches&title=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EWhat+can+we+learn+from+the+Capita+data+breaches%3F%3C%2Fspan%3E>

## Recent Posts

![](https://blog.grantmcgregor.co.uk/hubfs/Shadow%20AI%20-%20Is%20Your%20Business%20Ready%20for%20AI%20Adoption.png)

### Shadow AI: Is Your Business Ready for AI Adoption?

 Understand shadow AI's impact on your business. Discover how to assess risks, improve processes, and adopt AI securely w...

[Read More](https://blog.grantmcgregor.co.uk/shadow-ai-is-your-business-ready-for-ai-adoption)

![Our Net Zero Target for 2040 - What Can We Change](https://blog.grantmcgregor.co.uk/hubfs/Our%20Net%20Zero%20Target%20for%202040%20-%20What%20Can%20We%20Change.png)

### Our Net Zero Target for 2040: What Can We Change?

 From company vehicles and travel to suppliers and technology, see how Grant McGregor is working towards its net zero tar...

[Read More](https://blog.grantmcgregor.co.uk/our-net-zero-target-for-2040-what-can-we-change)

![](https://blog.grantmcgregor.co.uk/hubfs/What%20Is%20Penetration%20Testing%3F%20A%20Guide%20for%20Businesses.png)

### What Is Penetration Testing? A Guide for Businesses

 Learn what penetration testing is, how it works, what the report should include and when your business should consider a...

[Read More](https://blog.grantmcgregor.co.uk/what-is-penetration-testing-a-guide-for-businesses)

![Grant McGregor named 2026 Top Managed Service Provider](https://blog.grantmcgregor.co.uk/hubfs/Social/MSP%20501%202026%20Winner.png)

### Grant McGregor Recognised as a Leading Global MSP in the 2026 MSP 501

 Grant McGregor has been named a Top Global Managed Service Provider in the 2026 MSP 501, ranking #1 Scotland-based MSP a...

[Read More](https://blog.grantmcgregor.co.uk/grant-mcgregor-recognised-as-a-leading-global-msp-in-the-2026-msp-501)

Union

## Empower your business with secure, expert-led solutions.

Talk to us about people-focused technology that drives results.

[Start a conversation](https://grantmcgregor.co.uk/contact-us)

![](https://blog.grantmcgregor.co.uk/hubfs/Woman%20in%20White%20longsleeve%20polo.png)

![Divider Footer](https://blog.grantmcgregor.co.uk/hubfs/footer.svg)

![GrantMcGeregor Logo White](https://blog.grantmcgregor.co.uk/hubfs/McGregor%20Theme%20Assets/GRMC_white_logo-cropped.svg "GrantMcGeregor Logo White")

Premium IT Services Tailored for Leading Brands

[Follow us on LinkedIn](https://www.linkedin.com/company/grant-mcgregor-ltd/) [Follow us on Facebook](https://www.youtube.com/itgrantmcgregor) [Follow us on Facebook](https://www.facebook.com/grantmcgregorltd/) [Follow us on Twitter](https://x.com/GrantMcGregorIT)

Quick Links

- [Home](https://grantmcgregor.co.uk)
- [About us](https://grantmcgregor.co.uk/about-us/our-story)
- [Knowledge Hub](https://grantmcgregor.co.uk/knowledge-hub/blog)
- [Contact us](https://grantmcgregor.co.uk/contact-us)

Services

- [People Centric Support](https://grantmcgregor.co.uk/it-support-services/people-centric-support)
- [Enhanced Security Service](https://grantmcgregor.co.uk/it-support-services/enhanced-security-service)
- [Professional IT Services](https://grantmcgregor.co.uk/professional-it-services)
- [Cyber Security](https://grantmcgregor.co.uk/cyber-security)

Edinburgh – Chesterfield

![Phone icon](https://blog.grantmcgregor.co.uk/hubfs/raw_assets/public/GrandMcGregor_climb/images/tel.png "Phone icon")

[0131 603 7910](tel:+441316037910)

![Email icon](https://blog.grantmcgregor.co.uk/hubfs/raw_assets/public/GrandMcGregor_climb/images/mail.png "Email icon")

[info@grantmcgregor.co.uk](mailto:info@grantmcgregor.co.uk)

![Location icon](https://blog.grantmcgregor.co.uk/hubfs/raw_assets/public/GrandMcGregor_climb/images/loc.png "Location icon")

**Main Office:**   
The Merchants' Hall,  
22 Hanover St,  
Edinburgh EH2 2EP

 © 2026

Grant McGregor. All rights reserved.

[Privacy and Cookie Policy](https://blog.grantmcgregor.co.uk/hubfs/UsefulDownloads/Policies/GRMC-SEC-Privacy-and-Cookie-Policy.pdf)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Grant McGregor Team",
    "url" : "https://blog.grantmcgregor.co.uk/author/grmc-team"
  },
  "dateModified" : "2023-06-07T08:33:04.334Z",
  "datePublished" : "2023-06-07T08:33:04.000Z",
  "headline" : "What can we learn from the Capita data breaches?",
  "image" : [ "https://blog.grantmcgregor.co.uk/hubfs/data%20breach.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.grantmcgregor.co.uk/what-can-we-learn-from-the-capita-data-breaches",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.grantmcgregor.co.uk/hubfs/GRMC_blue_logo.svg"
    },
    "name" : "Grant McGregor"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://grantmcgregor.co.uk/",
  "@type" : "LocalBusiness",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "GB",
    "addressLocality" : "Edinburgh",
    "postalCode" : "EH2 2EP",
    "streetAddress" : "22 Hanover Street"
  },
  "geo" : {
    "@type" : "GeoCoordinates",
    "latitude" : 55.9526313,
    "longitude" : -3.1970679
  },
  "image" : "https://grantmcgregor.co.uk/hubfs/GRMC_blue_logo.svg",
  "name" : "Grant McGregor",
  "openingHoursSpecification" : {
    "@type" : "OpeningHoursSpecification",
    "closes" : "18:00",
    "dayOfWeek" : [ "Monday", "Tuesday", "Wednesday", "Thursday", "Friday" ],
    "opens" : "08:00"
  },
  "sameAs" : [ "https://www.facebook.com/grantmcgregorltd/", "https://x.com/GrantMcGregorIT", "https://www.youtube.com/itgrantmcgregor", "https://www.linkedin.com/company/grant-mcgregor-ltd/" ],
  "telephone" : "+441316037910",
  "url" : "https://grantmcgregor.co.uk/"
}
```