National IT consulting firm suffers data breach.

24th April 2023Personal data breach

National IT consulting firm suffers data breach.

If it can happen to them, it can happen to you.

UK-based professional services firm Capita has confirmed that hackers may have stolen data from its systems following a cyber-attack in March. The cyber incident primarily impacted access to internal Microsoft Office 365 applications.

Capita plc provides IT consulting and outsourcing services to clients across the private and public sector, including the Government, local tax authorities, the Royal Navy, and Network Rail, reputed to be worth £6.5 billion.

In a news release on 3 April 2023, Capita stated:

“On Friday 31 March, Capita plc experienced a cyber incident. . .this caused disruption… there is no evidence of customer, supplier or colleague data having been compromised” Capita plc.

However, as they investigated the cause of the incident with their cyber forensic experts and specialist advisers, it came to light that as a result of the cyber attack, there IS evidence of what Capita is calling ‘data exfiltration’. This resulted in a further announcement from Capita on 20 April 2023:

“From our investigations to date, it appears that the incident arose following initial unauthorised access on or around 22 March and was interrupted by Capita on 31 March. As a result of the interruption, the incident was significantly restricted, potentially affecting around 4% of Capita’s server estate. There is currently some evidence of limited data exfiltration from the small proportion of affected server estate which might include customer, supplier or colleague data..” Capita plc.

The company has said it is continuing to investigate the attack to determine to what extent the cyber attackers may have accessed customer, supplier or colleague data.

What rings alarm bells here is not just the fact that they were breached but that the hackers had access from 22 March until 31 March 2023.

On 21 April, an ICO spokesperson confirmed that a breach had been reported:

“Capita has reported an incident to us and we are assessing the information provided.

Other organisations who are affected should also consider their position and report data breaches where necessary. Organisations must notify the ICO within 72 hours of becoming aware of a personal data breach unless it does not pose a risk to people’s rights and freedoms.

If an organisation decides that a breach doesn’t need to be reported they should keep their own record of it, and be able to explain why it wasn’t reported if necessary.”

The Sunday Times is claiming that Capita is playing down the breach. They say this because a cyber-attacking group named Black Basta have claimed they are responsible and are listing the data they have stolen from Capita for sale: This includes personal data.

You can understand WHY Capita would want to play down the breach, any breach is terrible PR for a company, and their falling share price reflects this. Mishandling the reporting of the breach or trying to cover it up (there is no suggestion that Capita did this) – only damages your reputation further.

Historically hackers stole data in order to simply sell the data, or they used Ransomware to elicit money, and that was their end game.  However, hackers are becoming more sophisticated.  They know that the mere mention of a breach causes share prices to fall, so they are in a position to manipulate the stock market.

If you believe you have suffered a data breach, you MUST report it immediately to the appropriate Data Protection Authority, and in the UK, this must be done within 72 hours. This will a) ensure that you comply with your legal obligation and b) will help to restore trust more quickly.

Why did a national IT consulting firm suffers a data breach?

The answer remains to be seen at this stage, as their investigations are ongoing.

According to Computer Weekly.com, the way Black Basta has operated in the past is via a zip file in a phishing email.

If you are unfamiliar with the term phishing email – please get some training in place immediately. (Phishing emails are cleverly disguised emails pretending to be something they are not – they often contain a virus or are sent to extort money).

Prevention of a data breach

The Integrity and Confidentiality Principle in the UK GDPR obligates Controllers to implement appropriate technical and organisational measures to prevent unauthorised access to or loss of personal data. Article 32 and Recital 78 specifically concern the security of processing personal data.

Measures expected from organisations include the pseudonymisation and encryption of personal data and implementing sufficient technical measures such as firewalls, antivirus software, virtual private networks, multi-factor authentication and robust access controls. Controllers must both have in place and be able to demonstrate that they are managing the ongoing confidentiality, integrity, availability and resilience of processing systems and services. They must ensure that authorised users can access personal data when required and be able to restore personal data promptly in the event of a physical or technical incident.

Ongoing oversight and governance must account for the regular testing, assessing and evaluating the effectiveness of technical and organisational measures to ensure the security of the processing.

If any of the above makes you feel nervous regarding your own organisation, please take advantage of your complimentary thirty-minute consultation with one of our data protection specialists, or book one of our training courses here.

If you are seriously concerned about a data breach or want to give yourself and your organisation complete peace of mind, Cordery Compliance, one of our trusted partners, runs a full-day Data Breach Academy.  Find out more about their Data Breach Academy here.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details