Capita Confirms Data Stolen in Ransomware Attack
Capita, an outsourcing firm based in London, has released an update confirming that hackers stole data from its systems in a cyber incident that occurred in March. Capita provides critical services to various UK government departments, including the NHS, the military, and the Department for Work and Pensions. However, the company has not disclosed how many clients have been affected or the type of data accessed.
According to Capita’s statement, security specialists discovered that the hackers accessed around 4% of the company’s infrastructure.The statement confirms that there is proof of a small-scale data exfiltration from the impacted systems, which may include customer, supplier, or employee data.
Capita is conducting an ongoing investigation into the incident and has committed to providing updates if any evidence emerges that could potentially affect its customers, suppliers, or employees. The company initially did not reveal much about the nature of the attack when it was first disclosed at the end of March.
The most recent update reveals that the hackers obtained unauthorized access to Capita’s systems on 22nd March and continued their activity until 31st March, when the company became aware of the ongoing breach and interrupted it.
The outage caused by the attack prevented access to Capita’s internal Microsoft Office 365 applications and reduced the availability of client systems, including those of state organizations in the UK.
The Black Basta ransomware group posted Capita on its site on the dark web using a private link on 17th April, threatening to sell stolen data unless a ransom was paid. Among the data samples posted by Black Basta were personal bank account details, physical addresses, passport scans, and other sensitive information. The group is also believed responsible for a recent attack on US satellite television provider Dish.
The company has not confirmed whether these claims are valid or provided public comment on Black Basta’s allegations. Capita’s entry on Black Basta’s site is still private, which Bleeping Computer has suggested might mean that the ransom payment is currently being negotiated. A spokesperson for Capita declined to comment on the allegations or whether the company has had any communication with the threat actors.
Please, comment on how to improve this article. Your feedback matters!