Skip to main content

Capita has agreed to pay a £14 million ($18.7 million) fine to the UK Information Commissioner’s Office (ICO) for failing to protect personal data during a 2023 cyberattack that exposed the information of 6.7 million individuals, the company announced on Wednesday.

The ICO said Capita lacked proper safeguards to prevent unauthorized access and failed to act on security alerts that could have limited the damage. The regulator emphasized that organizations must treat data protection as a top priority amid a sharp rise in large-scale cyberattacks.

“With so many cyber attacks in the headlines, our message is clear: every organisation, no matter how large, must take proactive steps to keep people’s data secure,” said Information Commissioner John Edwards.

Capita, which serves clients across the public and corporate sectors, had earlier warned the breach could result in up to £20 million in financial losses. Following the attack, the company said it has enhanced its cybersecurity framework and added advanced protective systems.

“After an extended dialogue with the ICO over the last two years, we are pleased to have concluded this matter,” said CEO Adolfo Hernandez. The firm now projects a free cash outflow of £59–79 million in 2025, slightly above earlier estimates.

The fine highlights growing regulatory scrutiny of UK firms following recent cyber incidents at Marks & Spencer, Co-op, and Jaguar Land Rover. The National Cyber Security Centre recently reported that “highly significant” cyber incidents have doubled year-on-year in Britain.