Capita Faces Lawsuit from Over 600 Scottish Victims after Massive Cyber Attack

More than 600 Scottish victims whose personal information was hacked in a massive cyber attack in March 2023 are suing Capita, the UK outsourcing giant. The attack, which compromised home addresses, passport images, and financial data, resulted in a £14 million fine from the UK's data watchdog, the Information Commissioner's Office (ICO). The ICO found that Capita failed to ensure the security of processing of personal data, leaving it at "significant risk." The firm, which made £2.4 billion in revenue last year, manages administration for over 600 pension schemes, with 325 affected.

Key Takeaways:

  • Over 600 Scottish victims are suing Capita for compensation after their personal information was hacked in a massive cyber attack in March 2023.
  • The attack compromised home addresses, passport images, and financial data, resulting in a £14 million fine from the ICO.
  • The ICO found that Capita failed to ensure the security of processing of personal data, leaving it at "significant risk."
  • Capita's CEO, Adolfo Hernandez, claimed the firm had "hugely strengthened" its cyber-security resilience after the attack.
  • The ICO's John Edwards found that Capita failed in its duty to protect the data entrusted to it by millions of people.
  • Thompsons Solicitors Scotland, representing the victims, has made significant progress in obtaining compensation for its clients.

Amy Haughton, of Thompsons Solicitors Scotland, stated that the ICO's findings of serious failings in Capita's security do not help the victims who suffered huge distress after their personal and sensitive data was compromised.

Statistics:

  • £14 million: the fine imposed on Capita by the ICO for failing to ensure the security of processing of personal data.
  • 600+: the number of Scottish victims suing Capita for compensation.
  • 325: the number of pension schemes affected by the attack, administered by Capita.
  • £2.4 billion: the revenue made by Capita last year.
  • 58 hours: the time the attacker was able to exploit Capita's systems without being detected.
  • "Significant risk": the level of risk posed by Capita's failure to ensure the security of processing of personal data, as stated by the ICO.

Sources:

  • "Information Commissioner's Office." (no date)
  • Thompsons Solicitors Scotland (no date)