Threat reportRansomwareTL-2026-0767

Capita Black Basta Ransomware Incident (March 2023) — Record £14M UK ICO Fine for 6M+ Affected Individuals

highRESOLVED

Capita Black Basta Ransomware Incident (March 2023) (TL-2026-0767), also tracked as Capita 2023 ransomware breach, is a high-severity ransomware operation, first published 2026-06-10. It is attributed to Black Basta with high confidence, affects Capita plc Capita corporate IT estate / Active Directory, maps to 24 MITRE ATT&CK techniques (T1003, T1018, T1021), and is covered by 9 detection rules and 26 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
1Black Basta
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-0767

Threat ID
TL-2026-0767
Also known as
Capita 2023 ransomware breach, Capita data breach
Severity
HIGH
Status
RESOLVED
Category
RANSOMWARE
First published
Last reviewed
Attribution
Black Basta
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
outsourcing, government, pensions, financial, public-sector
Target regions
United Kingdom, Europe
Detection rules
9
Indicators of compromise
26

Malware and tooling in Capita Black Basta Ransomware Incident (March 2023)

Malware and tooling: QakBot, SystemBC - S9001, BloodHound - S0521, Cobalt Strike, Mimikatz, Rclone - S1040

How Capita Black Basta Ransomware Incident (March 2023) works

In March 2023 the Black Basta ransomware group breached UK outsourcing giant Capita, gaining initial access via a Qakbot infection, deploying Cobalt Strike, SystemBC, rclone and BloodHound to compromise Active Directory and obtain domain-admin access, then exfiltrating nearly 1TB of data before detonating ransomware. A high-priority security alert went unactioned for over 58 hours. The UK ICO later issued a record £14 million ransomware-case fine (£8M against Capita plc, £6M against Capita Pension Solutions) over the breach of more than 6 million people's data.

On 22 March 2023 a malicious file was inadvertently downloaded onto a Capita employee's device, initiating the intrusion that the UK Information Commissioner's Office (ICO) detailed across a 136-page penalty report. A high-priority security alert was raised within roughly 10 minutes and some automated action was taken, but Capita did not quarantine the compromised device for over 58 hours — a window that vastly exceeded the contractual 1-hour SLA for high-severity (P2) alerts and during which the attacker established a foothold, moved laterally, and accessed credentials. Alerts during this period reportedly carried terms such as 'Threat Alert High,' 'Credential access,' and 'Lateral movement.'

The intrusion follows the well-documented Black Basta affiliate playbook. Initial access was achieved through Qakbot (Qbot), which establishes backdoor access and is commonly used to stage SystemBC (a SOCKS5 proxy/C2 tunneling implant). Cobalt Strike was deployed for command-and-control, reconnaissance, and additional tooling delivery. BloodHound was used for Active Directory enumeration to map attack paths to privileged accounts. A prior Capita penetration test had explicitly flagged that 'there are no policies preventing domain admins logging onto standard member servers' — exactly the weakness that enabled lateral movement and domain-administrator credential compromise. With domain-admin control established, the actor used rclone (and SystemBC tunneling) to exfiltrate nearly one terabyte of data between 29 and 30 March 2023.

On 31 March 2023 Black Basta deployed ransomware across Capita systems and reset all user passwords, locking staff out of their network. The same day, Capita publicly stated there was 'no evidence' of customer data compromise — a claim contradicted by the ~1TB exfiltration. The stolen data affected more than 6 million individuals and included highly sensitive categories: pension and staff records, criminal-records-check data, sexual-orientation data, political opinions, and biometric information. In October 2025 the ICO announced a £14 million fine — its largest in any ransomware case — split as £8 million against Capita plc and £6 million against Capita Pension Solutions Limited, settled voluntarily for under a third of the £45M the regulator had initially signalled. The case is a landmark example of how SOC alert-handling failure (an unactioned high-severity alert) directly enabled a catastrophic data breach.

MITRE ATT&CK techniques used in TL-2026-0767

Credential Access

T1003 OS Credential Dumping

Discovery

T1018 Remote System Discovery; T1087 Account Discovery; T1482 Domain Trust Discovery

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts

Defense Evasion

T1070 Indicator Removal

Command and Control

T1071 Application Layer Protocol; T1219 Remote Access Tools; T1572 Protocol Tunneling

Persistence

T1133 External Remote Services; T1547 Boot or Logon Autostart Execution

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1531 Account Access Removal

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Capita Black Basta Ransomware Incident (March 2023)

  • Capita plc — Capita corporate IT estate / Active Directory
    Vulnerable versions: March 2023 environment
  • Capita Pension Solutions Limited — Pension administration data systems
    Vulnerable versions: March 2023 environment

Remediation for Capita Black Basta Ransomware Incident (March 2023)

Patches

  • Patch privilege-escalation vectors abused by Black Basta affiliates: ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42278/CVE-2021-42287), PrintNightmare (CVE-2021-34527), ConnectWise ScreenConnect (CVE-2024-1709)

Immediate actions

  • Enforce SOC SLAs for high-severity alerts and ensure rapid host quarantine/isolation — the 58-hour delay was the decisive failure
  • Hunt for and block Qakbot, SystemBC, Cobalt Strike, rclone and BloodHound activity across the estate
  • Block known Black Basta C2 domains and IPs at the perimeter and DNS layer

Workarounds

  • Segment Active Directory tiers and limit lateral SMB/RDP paths
  • Apply LSASS protection (Credential Guard / RunAsPPL) to blunt Mimikatz credential theft

Longer-term hardening

  • Implement tiered administration: prohibit domain admins from logging onto standard member servers (the exact weakness flagged in Capita's prior pentest)
  • Deploy EDR with behavioral detection and ensure containment actions are evidenced and verified, not assumed
  • Restrict and monitor rclone/WinSCP and other bulk data-transfer tooling; alert on large outbound transfers to cloud storage (e.g. Mega)
  • Implement phishing-resistant MFA and disable macros/restrict execution of mark-of-the-web files

Weaknesses (CWE) in Capita Black Basta Ransomware Incident (March 2023)

CWE-1188, CWE-269, CWE-522, CWE-693

Timeline of Capita Black Basta Ransomware Incident (March 2023)

  • Black Basta ransomware-as-a-service first identified, operating a double-extortion model and frequently using Qakbot for initial access.
  • Despite alerts referencing 'Threat Alert High,' 'Credential access,' and 'Lateral movement,' the compromised device was not quarantined; the high-severity alert went unactioned for over 58 hours, far exceeding the 1-hour SLA.
  • Malicious file inadvertently downloaded onto a Capita employee device; a high-priority security alert was raised within ~10 minutes and some automated action taken.
  • During the 58-hour window the attacker exploited the foothold, moved laterally, and compromised Active Directory domain-administrator credentials (aided by the absence of policy preventing domain admins logging onto member servers).
  • Bulk data staging and exfiltration began using rclone with SystemBC tunneling.
  • Nearly one terabyte of data exfiltrated from Capita systems.
  • Capita publicly stated there was 'no evidence' of customer data compromise — contradicted by the ~1TB exfiltration.
  • Black Basta deployed ransomware across Capita systems and reset all user passwords, locking staff out of the network.
  • Breach affected more than 6 million individuals, including pension/staff records, criminal-records-check data, sexual orientation, political opinions, and biometric data.
  • CISA/FBI published #StopRansomware: Black Basta advisory (AA24-131A) documenting affiliate TTPs and IOCs; updated 8 November 2024.
  • UK ICO fined Capita £14 million (£8M Capita plc + £6M Capita Pension Solutions) — its largest fine in a ransomware case — settled for under a third of the initially signalled £45M.

Sources cited for Capita Black Basta Ransomware Incident (March 2023)

Detection coverage for TL-2026-0767

As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0767 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats