home.social

#capita — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #capita, aggregated by home.social.

fetched live
  1. As of the end of 2025, the public overall budget registered a debt of €2,662.2 billion in the non-public sector. According to definitive results released by the... news.osna.fm/?p=57168 | #news #capita #debt #german #hits

  2. New letter today.
    This one is a IN01AC to go along with the IN01O0 (2 of those).

    They have opened at least 6 "official investigation"s in the 2 years we've lived here, but they still have no clue who we are.

    19 letters on file, 2 thrown away.

    #tvl #tvlicence #capita #harassment

  3. 📰 UK Civil Service Pension Scheme Suffers Data Breach Under Capita's Troubled Administration

    🇬🇧 UK Civil Service Pension Scheme, run by Capita, suffers data breach. A technical glitch let 138 members view others' pension statements. The incident adds to ongoing 'serious issues' with Capita's contract. #DataBreach #UKGov #Capita

    🔗 cyber.netsecops.io/articles/uk

  4. Good news! The Civil Service Pension Scheme website can now show you an Annual Benefit Statement 😃 Bad news! Not necessarily *your* ABS 🙃 www.civilservicepensionscheme.org.uk/memberhub/kb... #Capita

  5. Good news! The Civil Service Pension Scheme website can now show you an Annual Benefit Statement 😃 Bad news! Not necessarily *your* ABS 🙃 www.civilservicepensionscheme.org.uk/memberhub/kb... #Capita

  6. #Capita plc has secured a four-year contract, with an option to extend for two more years, to provide contact centre services for #Transport for #London (TfL). The agreement covers handling 50% of voice calls from Oyster card users and managing all written correspondence, including emails and website forms. Staff training is underway, with phase one launching in mid-October. This contract builds on Capita’s existing work with #TfL, including managing London’s Road User Charging schemes and network services across TfL sites. Gavin Dunkley, Capita’s Transport Sector MD, highlighted the partnership’s role in supporting London’s transport, air quality, and accessibility goals, emphasising a smooth transition and quality service delivery.
    capita.com/news/capita-awarded

  7. One misstep led to a cybersecurity nightmare: a 58-hour delay turned a single click into a breach affecting 6.6 million people and a £14m fine. How did Capita’s lapse spiral into chaos, and what does it mean for our digital safety?

    thedefendopsdiaries.com/the-an

    #databreach
    #capita
    #cybersecurity
    #incidentresponse
    #ransomware
    #infosec
    #regulatorycompliance

  8. One misstep led to a cybersecurity nightmare: a 58-hour delay turned a single click into a breach affecting 6.6 million people and a £14m fine. How did Capita’s lapse spiral into chaos, and what does it mean for our digital safety?

    thedefendopsdiaries.com/the-an

    #databreach
    #capita
    #cybersecurity
    #incidentresponse
    #ransomware
    #infosec
    #regulatorycompliance

  9. The full Capita report is available here:

    ico.org.uk/media2/pv5nhks4/cap

    A significant portion of the report is Capita arguing with the ICO that it doesn’t have the remit, and the ICO saying “Sure Jan” and then Capita agreeing the fine.

    Tl;dr love your SOC. And fix Active Directory. The threat actor actually deployed BloodHound before Capita. And don’t try to cover up your breaches.

    #Capita

  10. The full Capita report is available here:

    ico.org.uk/media2/pv5nhks4/cap

    A significant portion of the report is Capita arguing with the ICO that it doesn’t have the remit, and the ICO saying “Sure Jan” and then Capita agreeing the fine.

    Tl;dr love your SOC. And fix Active Directory. The threat actor actually deployed BloodHound before Capita. And don’t try to cover up your breaches.

    #Capita

  11. The ICO finds the Capita was negligent when it comes to cybersecurity, particularly highlighting the SOC and Active Directory security. #Capita

  12. The ICO finds the Capita was negligent when it comes to cybersecurity, particularly highlighting the SOC and Active Directory security. #Capita

  13. The ICO note Capita sell a Managed SOC service to the UK government.. but failed to run its own SOC properly. #Capita

  14. The ICO note Capita sell a Managed SOC service to the UK government.. but failed to run its own SOC properly. #Capita

  15. Capita claim none of the exfiltrated data was available on the dark web - which is actually false if you read this thread, The Times got data from the portal and called the victims (teachers Capita vetted).

    Nevertheless, the ICO doesn’t agree anyway - there is still a risk of harm even if you pay the ransom and try to cover up the data theft, basically.

    #Capita

  16. Capita claim none of the exfiltrated data was available on the dark web - which is actually false if you read this thread, The Times got data from the portal and called the victims (teachers Capita vetted).

    Nevertheless, the ICO doesn’t agree anyway - there is still a risk of harm even if you pay the ransom and try to cover up the data theft, basically.

    #Capita

  17. The ICOs view is orgs should be treating CobaltStrike as a P1 and immediately isolate systems pending investigation. #Capita

  18. The ICOs view is orgs should be treating CobaltStrike as a P1 and immediately isolate systems pending investigation. #Capita

  19. Capita had written down that it responds to all P2 alerts in its SOC with 45 minutes. It actually took them several days to reach the initial alert. They were never reaching their internal SLA.

    They argued with the ICO that it is not able to regulate its internal SLAs and its regulatory overreach.. the ICO took a different view.

    #Capita

  20. Capita had written down that it responds to all P2 alerts in its SOC with 45 minutes. It actually took them several days to reach the initial alert. They were never reaching their internal SLA.

    They argued with the ICO that it is not able to regulate its internal SLAs and its regulatory overreach.. the ICO took a different view.

    #Capita

  21. Capita says their systems had Nessus vulnerability scans. The ICO notes this is not a silver bullet, and that recurring penetration tests should take place. It found the business unit with exfiltrated data never had a pen test. #Capita

  22. Capita says their systems had Nessus vulnerability scans. The ICO notes this is not a silver bullet, and that recurring penetration tests should take place. It found the business unit with exfiltrated data never had a pen test. #Capita

  23. Here’s the data stolen. This included my data, as I had used their employee vetting scheme at the time (for a different company). #Capita

  24. Here’s the data stolen. This included my data, as I had used their employee vetting scheme at the time (for a different company). #Capita

  25. Capita had the PII of 6 million people exfiltrated.. but aren’t exactly sure how many still.

    Additionally, they already had a major security incident running and external IR in before the encryption - while this incident was running, the attacker stole a terabyte of data over several days. The cause? No containment. They didn’t contain when they knew the attacker was on the network.

    #Capita

  26. Capita had the PII of 6 million people exfiltrated.. but aren’t exactly sure how many still.

    Additionally, they already had a major security incident running and external IR in before the encryption - while this incident was running, the attacker stole a terabyte of data over several days. The cause? No containment. They didn’t contain when they knew the attacker was on the network.

    #Capita

  27. This thread is almost 1000 days old and getting a resurrection. #Capita have been fined £14m by the ICO over their ransomware incident.

    Lots of big details in the fine, including over 1tb of data stolen (as detailed in this Mastodon thread at the time), confirmation of Qakbot and my blog etc.

    Their SOC was wildly understaffed. It took attacker 4 hours to get domain admin due to poor security practices. Lots of learnings for large orgs.

  28. This thread is almost 1000 days old and getting a resurrection. #Capita have been fined £14m by the ICO over their ransomware incident.

    Lots of big details in the fine, including over 1tb of data stolen (as detailed in this Mastodon thread at the time), confirmation of Qakbot and my blog etc.

    Their SOC was wildly understaffed. It took attacker 4 hours to get domain admin due to poor security practices. Lots of learnings for large orgs.

  29. Yesterday we were discussing the need to get Cyber Essentials certification because Capita demands it.

    Capita.

    #databreach #capita #irony

  30. Yesterday we were discussing the need to get Cyber Essentials certification because Capita demands it.

    Capita.

    #databreach #capita #irony

  31. Ex academics or those who know about the recent Capita breach - can you help or advise? Im sharing this anonymously, but it concerns someone I know.

    #privacy #data #breach #capita #academicmastodon #academicchatter

  32. Ex academics or those who know about the recent Capita breach - can you help or advise? Im sharing this anonymously, but it concerns someone I know.

    #privacy #data #breach #capita #academicmastodon #academicchatter

  33. @wood5y
    My works pension is with them. Now all my details are with the Chinese. 'Sorry' did not seem to be enough!
    #Capita
    #ChinaIsAnOrganisedCrimeGang

  34. Update: Ist bereits vergeben.

    Benötigt jemand 4 #IKEA #CAPITA-Beine, Edelstahl, 8 cm hoch, für einen Schrank oder einen seeeeeeehr niedrigen Tisch? 😁

    Ich möchte nur das Porto hierfür bzw. eine vorfrankierte Versandmarke (DHL-Päckchen S).

    #zuVerschenken #Wish2Hand #FediGive

  35. Update: Ist bereits vergeben.

    Benötigt jemand 4 #IKEA #CAPITA-Beine, Edelstahl, 8 cm hoch, für einen Schrank oder einen seeeeeeehr niedrigen Tisch? 😁

    Ich möchte nur das Porto hierfür bzw. eine vorfrankierte Versandmarke (DHL-Päckchen S).

    #zuVerschenken #Wish2Hand #FediGive

  36. #Capita’s new CEO has refused to say if they paid Black Basta ransomware group last year (they did). thetimes.co.uk/article/capita-

  37. #Capita’s new CEO has refused to say if they paid Black Basta ransomware group last year (they did). thetimes.co.uk/article/capita-

  38. #Capita cut the pension business out of their operational KPIs, citing the impact of the ransomware incident.

  39. #Capita cut the pension business out of their operational KPIs, citing the impact of the ransomware incident.

  40. It’s been almost a year since the #Capita ransomware incident began. Here’s how the new CEO describes it in their yearly update.

    There’s now some careful rewording around data exfiltration and “recovery activities” of said data.

    The exact amount they book for incident response and recovery is £25.3m, and they do not mention if insurance will cover. Overall the business has booked a £106.6m loss for the year.

  41. It’s been almost a year since the #Capita ransomware incident began. Here’s how the new CEO describes it in their yearly update.

    There’s now some careful rewording around data exfiltration and “recovery activities” of said data.

    The exact amount they book for incident response and recovery is £25.3m, and they do not mention if insurance will cover. Overall the business has booked a £106.6m loss for the year.

  42. Retired teacher’s pension stopped as provider refuses to believe she is not dead | The Guardian

    It seems that in the wake of the post office scandal people are finally starting to write “tech needs to do the right thing” stories again:

    https://www.theguardian.com/money/2024/jan/20/retired-teachers-pension-stopped-as-provider-refuses-to-believe-she-is-not-dead

    https://alecmuffett.com/article/108953

    #capita #databases #regulation