Day 25/31 The Delay That Cost Millions (Capita, 2023)
In 2023, Capita suffered a cyberattack that exposed data belonging to around 6.6 million people.
The breach began when a malicious file was unintentionally downloaded onto an employee’s device. Capita’s failure to quarantine the compromised device for 58 hours allowed attackers to exploit its systems further.
The Information Commissioner’s Office (ICO) later found that weak access controls, poor privilege management, and delayed containment contributed to the scale of the breach.
In October 2025, the ICO initially proposed a £45 million fine, which was later reduced to £14 million after Capita’s representations and the mitigating improvements it made following the incident.
Community Challenge
Do you think the fine is fair and justified? Give reasons?