Skip to content
CityAM
Main navigation
  • News
    • News
      • Latest Business News
      • Economics
      • Politics
      • Tech
      • Banking
      • FTSE 100 Live
      • Retail
      • Insurance
      • Legal
      • Property
      • Transport
      • Markets
    • From our partners
      • AON
      • Bayes Business School
      • Canada BIDs
      • Central London Alliance CIC
      • Destination City
      • Halkin
      • Olympia
      • Inside Saudi
      • Tottenham Hotspur Stadium
      • Santander X
      • YEAR SIX Dividend
    • Featured

      Would a £10bn VAT cut really save hospitality?

      Business professionals discussing strategies in a modern office setting with diverse team collaboration visible

      Submit a story

      Tell us your story.

      Submit
  • Opinion
  • Sport
    • Latest Sports News
      • Sport
      • Sport Business
    • From our partners
      • The Morning Briefing: SBS x CityAM
      • Aramco Team Series
      • LIV Golf
    • Featured

      Platitudes in women’s sport are empty, patronising and offensive

      Business professionals in a conference room discussing strategy with a presentation screen displaying key market trends.

      Submit a story

      Tell us your story.

      Submit
  • Life&Style
    • Life&Style
      • Life&Style
      • Toast the City Awards
      • The Magazine
      • Travel
      • Culture
      • Motoring
      • Wellness
      • The RED BULLETiN
      • Do it with Shared Ownership
      • Media Speak Hub
    • Featured

      Fogo de Chao nominated for Best Casual Dining Toast award

      Fogo de Chão restaurant exterior with vibrant signage and bustling entrance at popular city location

      Submit a story

      Tell us your story.

      Submit
  • Investec
  • Events
  • Latest Paper
Wednesday 15 October 2025 7:55 am

ICO fines Capita £14m after millions affected by data breach

By: Simon Hunt

City Editor

Add as a preferred source on Google
The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
law firms, are the "current flavour of the month" for cyberattacks

Capita has been fined £14m by the Information Commissioner’s Office (ICO) after millions were affected by its data breach.

The fine follows a cyber attack in 2023 in which the personal information of 6.6m people was stolen, from pension records and staff records to the details of customers of organisations Capita supports. 

For some, this included sensitive information such as details of criminal records, financial data or special category data.

The ICO said its investigation found that Capita had failed to ensure the security of personal data processing, leaving it at significant risk, and lacked the appropriate technical and organisational measures to respond to the attack effectively.

Capita did not implement a tiering model for administrative accounts, allowing attackers to escalate privileges, move laterally across multiple domains and compromise critical systems. The failings were flagged as a vulnerability on at least three separate occasions but were not remedied.

Capita’s data breach and its impact ‘could have been prevented’

“Capita failed in its duty to protect the data entrusted to it by millions of people. The scale of this breach and its impact could have been prevented had sufficient security measures been in place,” said Information Commissioner John Edwards.

“When a company of Capita’s size falls short, the consequences can be significant. Not only for those whose data is compromised – many of whom have told us of the anxiety and stress they have suffered – but for wider trust amongst the public and for our future prosperity. 

“As our fine shows, no organisation is too big to ignore its responsibilities.”

The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors” included security improvements made after the attack and support offered to affected individuals.

Capita plc was fined £8m while Capita Pension Solutions Limited was fined £6m, giving a combined total of £14m.

Capita chief executive Adolfo Hernandez said the company had “hugely strengthened our cybersecurity posture, built in advanced protections and embedded a culture of continuous vigilance.”

“Following an extended period of dialogue with the ICO over the last two years, we are pleased to have concluded this matter and reach today’s settlement,” Hernandez said.

Read more

Professional services firms the ‘flavour of the month’ for cyberattacks

The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

People & Organisations

  • Capita
  • cyber attack
  • cybersecurity
  • data breach
  • fine
  • Information Commissioner's Office
  • Information Commissioner’s Office (ICO)

Trending Articles

  • As it happened: Stocks sink after Fed and Bank of England opt for hawkish hold; Oil price tumbles

  • FTSE 100 Live: Pound dips and stocks slip as Andy Burnham victory triggers political uncertainty

  • City investors raise alarm on Burnham’s Chancellor pick

  • Inheritance tax enquiries surge to six-year high after HMRC clampdown

  • More Big Four blues as Deloitte plans to slash UK audit roles

More from CityAM

  • Professional services firms the ‘flavour of the month’ for cyberattacks

    Prof Services
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • UK ministers tell UK businesses to ‘step up’ cyber defences

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • ‘We cannot regulate cyber threats away,’ top lawyer warns

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • IMF warns AI cyberattacks could trigger global financial crisis

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • UK economy falters as deeper damage to growth to come

    Economics
    Rachel Reeves speaking at an IOD event.
  • Business doesn’t want a ‘partnership’ with the state

    Opinion
    Rachel Reeves speaking at an IOD event.
  • Lansdowne Partners launches VC fund to scale UK innovation to global commercial success

    Business Wire
  • GoldenSource and InvestOps Research Reveals Weak Data Foundations Are Putting AI Outcomes at Risk, Slowing Growth and Costing Investment Managers Billions

    Business Wire

CityAM Canada — business, markets and opinion for Canadian readers.

Sections

  • Business
  • Markets
  • Tech
  • AI
  • Economics
  • Opinion
  • Cities

Company

  • About
  • Contact

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 CityAM Canada. All rights reserved.
Terms · Privacy · Cookies