---
title: Capita Ransomware Incident Summary
description: On the 31st of March at 2:00pm, The Times reporter, Katie Prescott, published an article speculating on fears the UK outsourcing company Capita had been hit by a cyber-attack. Capita had previously issued a statement saying they are aware of a technical issue, but at this stage, did not answer whether it was a data breach.
image: https://csacyber.com/hubfs/capita-ransomware-main.jpg
---

[Skip to content](https://csacyber.com/blog/capita-ransomware-incident-summary#main-content)

[![CSA Cyber - Cyber Security Solutions to Protect your People](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=300&height=108&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber - Cyber Security Solutions to Protect your People")](https://csacyber.com/)

- Services 
    - [Offensive Security Services](https://csacyber.com/offensive-security-services) 
          - [Penetration Testing](https://csacyber.com/penetration-testing)
          - [Red Teaming and attack simulations](https://csacyber.com/offensive-security-services#red-teaming)
          - [Continuous testing](https://csacyber.com/offensive-security-services#continuous-assurance)
          - [Managed offensive security](https://csacyber.com/offensive-security-services#managed-offensive)
    - [Consultancy Services](https://csacyber.com/cyber-consultancy-services) 
          - [Frameworks & assessments](https://csacyber.com/cyber-consultancy-services/frameworks-and-assessments)
          - [Data protection](https://csacyber.com/cyber-consultancy-services#data-protection)
          - [Virtual leadership](https://csacyber.com/cyber-consultancy-services#virtual-leadership)
          - [Technical security consulting](https://csacyber.com/cyber-consultancy-services#technical-consultancy)
          - [Governance, Risk & Compliance (GRC)](https://csacyber.com/cyber-consultancy-services/governance-risk-and-compliance-services)
    - [Extended Managed Security Services](https://csacyber.com/extended-managed-security-services) 
          - [Microsoft Sentinel SIEM](https://csacyber.com/extended-managed-security-services#microsoft-sentinel)
          - [SOC services](https://csacyber.com/extended-managed-security-services#soc-services)
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/extended-managed-security-services#cyber-helpdesk)
    - [Incident Response Services](https://csacyber.com/incident-response-services) 
          - [Emergency Incident Response](https://csacyber.com/urgent/emergency-incident-response)
          - [Incident Response Retainer](https://csacyber.com/incident-response-services)
          - [Cyber Incident Readiness & Response Planning](https://csacyber.com/incident-response-services)
          - [Tabletop Exercises & Live-Range Engagements](https://csacyber.com/incident-response-services)
    - [Specialist Security Services](https://csacyber.com/specialist-services) 
          - [AI Security](https://csacyber.com/cyber-services-for-ai)
          - [Operational Technology (OT)](https://csacyber.com/specialist-services#operational-technology)
          - [Cyber security for Private Equity](https://csacyber.com/specialist-services#mergers-and-acquisitions)
          - [Cyber training and education](https://csacyber.com/specialist-services#training-and-education)
          - [Virtual leadership](https://csacyber.com/specialist-services#leadership)
    - [Cyber Technologies](https://csacyber.com/cyber-technologies) 
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/cyber-technologies#sentinelone)
          - [AppGuard Endpoint & Server Zero Trust Protection](https://csacyber.com/cyber-technologies#appguard)
          - [Qualys Vulnerability Management as a Service (VMaaS)](https://csacyber.com/cyber-technologies#qualys-vmaas)
          - [Lookout Mobile Device Protection](https://csacyber.com/cyber-technologies#lookout)
          - [ThreatER DNS Protection](https://csacyber.com/cyber-technologies#threater-dns)
          - [Cyber Security Awareness & Training platform](https://csacyber.com/cyber-technologies#boxphish)
- [About](https://csacyber.com/about-us) 
    - [Careers](https://csacyber.com/careers)
    - [Certifications](https://csacyber.com/certifications-and-awards)
- [Blog](https://csacyber.com/blog)
- [Support Centre](https://csacyber.com/support)
- Resources 
    - [Case Studies](https://csacyber.com/case-studies)
    - [Downloads & Reports](https://csacyber.com/downloads-and-reports)
    - [Webinars](https://csacyber.com/webinars)
    - [Partners](https://csacyber.com/partners)
    - [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)
- [Contact](https://csacyber.com/contact-us)

- Search Search
  
  Search

 April 27, 2023

 4 min read time

# Capita Ransomware Incident Summary

![Patryk Machowiak](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) [Written by: Patryk Machowiak -](https://csacyber.com/blog/author/patryk-machowiak)

[Article](https://csacyber.com/blog/tag/article), [Security Operations](https://csacyber.com/blog/tag/security-operations) 

![](https://csacyber.com/hubfs/capita-ransomware-main.jpg)

### Executive Summary

On the 31st of March at 2:00pm, The Times reporter, Katie Prescott, published an article speculating on fears the UK outsourcing company Capita had been hit by a cyber-attack. Capita had previously issued a statement saying they are aware of a technical issue, but at this stage, did not answer whether it was a data breach. Employees at the company reported being denied access and had been informed via text message not to attempt access or submit password recovery requests.

Over the next 2 weeks, Capita continued to release press statements confirming the IT issue was in fact a cyber-attack but boasting their impressive response, swift decision making and stating their response is a “blueprint for others to follow”.

Subsequently, on April 17th, the Black Basta ransomware gang claimed responsibility for the Capita hack by publishing example data in the public domain. Following this development, Capita took nearly a week to confirm that data was in fact stolen and that they had suffered a data breach. Investigators believe the ransomware gang had achieved access and exfiltrated data as early as March 22nd, over 1 week before Capita were made aware and published any statement leading to many citing the attack and response effort as an example of what not to do due to Capita’s lack of transparency and clarity to staff, investors and the public over the events which have occurred.

### Attack Summary

At 4:00 AM on the 31st March, Capita computer systems went offline with many staff unaware until they tried to log on at 7am. At this time, employees received a text from the company at explaining that there was a company-wide IT problem and requested that users do not try to access the VPN or submit password recovery requests. Capita issued an public update stating that it was aware of an IT issue affecting computer systems but did not think it was a cyber-attack.

Capita reported the issue was primarily impacting access to internal Microsoft Office 365 applications and that although it caused disruption to some services provided to individual clients, the majority of their client services remained in operation. After initially blaming an IT issue, on the 3rd April, Capita confirmed they experienced a cyber incident but claimed that no evidence of customer, supplier or colleague data compromise had been observed. From this point until the data was published, no further updates were released.

2 weeks later, on the 17th April, the Russian linked Black Basta ransomware group publicly claimed responsibility for the attack by posting Capita, as well as stolen passport photos, BACS payments lists and more, onto their dark web leak site. No information on the ransom demand had been made public, however, this now confirmed that the previously stated IT issue, was a direct result of a ransomware incident.

![image](https://csa.limited/assets/img/blog/cap-62.png)

Whilst no confirmation on whether Capita have paid the ransom demand has been issued, the Black Basta gang have since removed Capita and the associated evidence from its public listings leading speculation to believe, Capita at the very least have entered into negotiations with the hackers.

### Conclusions

Throughout the incident, Capita’s public statements have been sparse and untruthful leading to criticism on their lack of transparency and response efforts. As one of the United Kingdom’s largest outsourcers, supporting much of the country’s critical infrastructure and data, Capita’s customers, staff and investors have all been awaiting confirmation that their data and systems are unaffected. Capita’s initial statements to the press that the problems are an IT issue, even going as far as to say the issue is resolved, have fuelled speculation and distrust with the company, indicated by the markets 10% drop in their share price following Black Basta’s publication.

The incident has shown not just the importance of technical controls and containment functionality in a cyber-attack, but also the critical role of marketing, legal, public and investor relations teams in ensuring transparent, concise and correct communications can be issued and helping retain public image.

### Recommendations

The following actions are recommended for preventing and detecting a Black Basta ransomware attack:

- Ensure regular user awareness training is undertaken on identify and responding to phishing emails, especially those containing malicious attachments
- Block unnecessary file types on email filtering such as executables and ISOs
- Prevent end users from mounting new drives which are commonly used by adversaries to bypass malware protection filters
- Enable Tamper protection, anti-virus and EDR software and include monitoring for attempts to disable its functionality
- If not in use in the environment, monitor for AnyDesk, AteraAgent and Splashtop remote support tools being installed and used by attackers
- Monitor for indicators of CobaltStrike, Mimikatz and Qakbot as common initial access and post exploitation frameworks used by multiple threat actors
- Ensure EDR signatures are regularly updated and, if not configured, automated responses are enabled to quarantine and mitigate threats
- Create and regularly test incident response procedures and playbooks for containing and eradicating an incident
- Prepare template communications for staff, investors and the public when dealing with an incident so that all publications remain consistent

### References

Double Pulsar, [https://doublepulsar.com/black-basta-ransomware-group-extorts-capita-with-stolen-customer-data-capita-fumble-response-9c3ca6c3b283](https://doublepulsar.com/black-basta-ransomware-group-extorts-capita-with-stolen-customer-data-capita-fumble-response-9c3ca6c3b283)

HHS, [https://www.hhs.gov/sites/default/files/black-basta-threat-profile.pdf](https://www.hhs.gov/sites/default/files/black-basta-threat-profile.pdf)

Kroll, [https://www.kroll.com/en/insights/publications/cyber/black-basta-technical-analysis](https://www.kroll.com/en/insights/publications/cyber/black-basta-technical-analysis)

The Times, [https://www.thetimes.co.uk/article/capita-hit-by-it-breakdown-amid-fears-of-cyberattack-glxtvnm72](https://www.thetimes.co.uk/article/capita-hit-by-it-breakdown-amid-fears-of-cyberattack-glxtvnm72)

Capita, [https://www.capita.com/news/update-cyber-incident](https://www.capita.com/news/update-cyber-incident)

Related Posts

## You may also like this

[Similar Articles](https://csacyber.com/blog)

[![](https://csacyber.com/hs-fs/hubfs/20230510-N1005919-Edit1.jpg?width=624&height=427&name=20230510-N1005919-Edit1.jpg)](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 August 24, 2026

 2 min read

### [FluidOne Group appoints Charly Davis as Managing Director of CSA Cyber to advance its security-first strategy](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 Experienced industry leader joins FluidOne to strengthen integrated cyber, IT and secure networking...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Untitled%20design.jpg?width=624&height=427&name=Untitled%20design.jpg)](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 August 20, 2026

 2 min read

### [CSA Cyber and FluidOne named as suppliers on G-Cloud 15](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 CSA Cyber (CSA), part of the FluidOne Group, has been named as a supplier on Government Commercial...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Engineered%20to%20Endure%20Campaign%20Assets%20(2).png?width=624&height=427&name=Engineered%20to%20Endure%20Campaign%20Assets%20(2).png)](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 August 20, 2026

 6 min read

### [Why organisations lose security visibility without realising it](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 Before an organisation can understand risk, maintain control or respond effectively to emerging...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![CSA Cyber Logo FNL_Full Logo](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=3463&height=1248&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber Logo FNL_Full Logo")](https://csacyber.com/)

Established in 2013, Cyber Security Associates Limited trading as CSA Cyber provides cyber consultancy and cyber managed services which help to detect, protect and educate against the ever-changing cyber threat. We have built our team from a foundation of Government (ex-Military) and Commercially experienced specialists all holding current and relevant cyber certifications. Today our core services are based around a 24/7 Security Operations Centre (SOC) based in Gloucester.

#### News & Resources

- [Blog](https://csacyber.com/blog)
- [Case Studies](https://csacyber.com/case-studies)
- [Downloads & Reports](https://csacyber.com/downloads-and-reports)
- [Webinars](https://csacyber.com/webinars)
- [Careers](https://csacyber.com/careers)
- [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)

#### Quick Links

- [About Us](https://csacyber.com/about-us)
- [Certifications](https://csacyber.com/certifications-and-awards)
- [Our Parent Company](https://www.fluidone.com)
- [Partners](https://csacyber.com/partners)
- [Contact Us](https://csacyber.com/contact-us)
- [Anti Bribery Policy](https://csacyber.com/hubfs/CSAAnti-BriberyPolicy.pdf)
- [Complaints Policy](https://csacyber.com/hubfs/CSAComplaintsPolicy.pdf)
- [Corporate Social Responsibility Policy](https://csacyber.com/hubfs/CSACorporateSocialResponsibilityPolicy.pdf)
- [Slavery and Human Trafficking Statement](https://csacyber.com/hubfs/CSASlaveryandHumanTraffickingStatement.pdf)
- [NCSC CHECK Status Verification](https://www.ncsc.gov.uk/organisation/csa-cyber/check-penetration-testing)
- [CREST Approved Certification Verification](https://www.crest-approved.org/member_companies/csa-cyber/)

#### Contact Information

**United Kingdom - London**

Cyber Security Associates Ltd

5 Hatfields, London, SE1 9PG

 

**United Kingdom - Gloucester**

Cyber Security Associates Ltd

Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ

 

**Phone:** [+44(0) 300 303 4691](tel:03003034691)

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

**United States of America**

Cyber Security Associates Inc.

6010 W. Spring Creek Pkwy, Plano, Texas, 75024

 

**Phone:** [+1 469 750 1695](tel:14697501695) 

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

[![trust-pilot](https://csacyber.com/hs-fs/hubfs/trust-pilot.png?width=178&height=104&name=trust-pilot.png)](https://uk.trustpilot.com/review/csa.limited)

 

---

- [Website Terms of Use](https://csacyber.com/website-terms-of-use)
- [Website Privacy Policy](https://csacyber.com/privacy-notice)
- [Website Cookie Policy](https://csacyber.com/cookie-policy)

 Copyright 2026. Cyber Security Associates Ltd [Follow us on Facebook](https://www.facebook.com/CSALIMITED/) [Follow us on LinkedIn](https://www.linkedin.com/company/csa-cyber/) [Follow us on Twitter](https://twitter.com/cybersecurityis) [Follow us on Facebook](https://www.youtube.com/@cybersecurityassociateslim) [Follow us on Facebook](https://www.instagram.com/cybersecurityassociates)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Patryk Machowiak",
    "url" : "https://csacyber.com/blog/author/patryk-machowiak"
  },
  "dateModified" : "2024-12-06T13:13:32.285Z",
  "datePublished" : "2023-04-27T04:15:00.000Z",
  "headline" : "Capita Ransomware Incident Summary",
  "image" : [ "https://csacyber.com/hubfs/capita-ransomware-main.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://csacyber.com/blog/capita-ransomware-incident-summary",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://csacyber.com/hubfs/csacyber-logo-black-01.svg"
    },
    "name" : "Cyber Security Associates Ltd"
  }
}
```