Threat reportRansomwareTL-2026-0767
Capita Black Basta Ransomware Incident (March 2023) — Record £14M UK ICO Fine for 6M+ Affected Individuals
Capita Black Basta Ransomware Incident (March 2023) (TL-2026-0767), also tracked as Capita 2023 ransomware breach, is a high-severity ransomware operation, first published 2026-06-10. It is attributed to Black Basta with high confidence, affects Capita plc Capita corporate IT estate / Active Directory, maps to 24 MITRE ATT&CK techniques (T1003, T1018, T1021), and is covered by 9 detection rules and 26 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 24MITRE ATT&CK
- Actors
- 1Black Basta
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-0767
- Threat ID
- TL-2026-0767
- Also known as
- Capita 2023 ransomware breach, Capita data breach
- Severity
- HIGH
- Status
- RESOLVED
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Black Basta
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- outsourcing, government, pensions, financial, public-sector
- Target regions
- United Kingdom, Europe
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in Capita Black Basta Ransomware Incident (March 2023)
Malware and tooling: QakBot, SystemBC - S9001, BloodHound - S0521, Cobalt Strike, Mimikatz, Rclone - S1040
How Capita Black Basta Ransomware Incident (March 2023) works
In March 2023 the Black Basta ransomware group breached UK outsourcing giant Capita, gaining initial access via a Qakbot infection, deploying Cobalt Strike, SystemBC, rclone and BloodHound to compromise Active Directory and obtain domain-admin access, then exfiltrating nearly 1TB of data before detonating ransomware. A high-priority security alert went unactioned for over 58 hours. The UK ICO later issued a record £14 million ransomware-case fine (£8M against Capita plc, £6M against Capita Pension Solutions) over the breach of more than 6 million people's data.
On 22 March 2023 a malicious file was inadvertently downloaded onto a Capita employee's device, initiating the intrusion that the UK Information Commissioner's Office (ICO) detailed across a 136-page penalty report. A high-priority security alert was raised within roughly 10 minutes and some automated action was taken, but Capita did not quarantine the compromised device for over 58 hours — a window that vastly exceeded the contractual 1-hour SLA for high-severity (P2) alerts and during which the attacker established a foothold, moved laterally, and accessed credentials. Alerts during this period reportedly carried terms such as 'Threat Alert High,' 'Credential access,' and 'Lateral movement.'
The intrusion follows the well-documented Black Basta affiliate playbook. Initial access was achieved through Qakbot (Qbot), which establishes backdoor access and is commonly used to stage SystemBC (a SOCKS5 proxy/C2 tunneling implant). Cobalt Strike was deployed for command-and-control, reconnaissance, and additional tooling delivery. BloodHound was used for Active Directory enumeration to map attack paths to privileged accounts. A prior Capita penetration test had explicitly flagged that 'there are no policies preventing domain admins logging onto standard member servers' — exactly the weakness that enabled lateral movement and domain-administrator credential compromise. With domain-admin control established, the actor used rclone (and SystemBC tunneling) to exfiltrate nearly one terabyte of data between 29 and 30 March 2023.
On 31 March 2023 Black Basta deployed ransomware across Capita systems and reset all user passwords, locking staff out of their network. The same day, Capita publicly stated there was 'no evidence' of customer data compromise — a claim contradicted by the ~1TB exfiltration. The stolen data affected more than 6 million individuals and included highly sensitive categories: pension and staff records, criminal-records-check data, sexual-orientation data, political opinions, and biometric information. In October 2025 the ICO announced a £14 million fine — its largest in any ransomware case — split as £8 million against Capita plc and £6 million against Capita Pension Solutions Limited, settled voluntarily for under a third of the £45M the regulator had initially signalled. The case is a landmark example of how SOC alert-handling failure (an unactioned high-severity alert) directly enabled a catastrophic data breach.
MITRE ATT&CK techniques used in TL-2026-0767
Credential Access
Discovery
T1018 Remote System Discovery; T1087 Account Discovery; T1482 Domain Trust Discovery
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts
Defense Evasion
Command and Control
T1071 Application Layer Protocol; T1219 Remote Access Tools; T1572 Protocol Tunneling
Persistence
T1133 External Remote Services; T1547 Boot or Logon Autostart Execution
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1531 Account Access Removal
Initial Access
Resource Development
defense-impairment
Affected products and versions in Capita Black Basta Ransomware Incident (March 2023)
- Capita plc — Capita corporate IT estate / Active Directory
Vulnerable versions: March 2023 environment - Capita Pension Solutions Limited — Pension administration data systems
Vulnerable versions: March 2023 environment
Remediation for Capita Black Basta Ransomware Incident (March 2023)
Patches
- Patch privilege-escalation vectors abused by Black Basta affiliates: ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42278/CVE-2021-42287), PrintNightmare (CVE-2021-34527), ConnectWise ScreenConnect (CVE-2024-1709)
Immediate actions
- Enforce SOC SLAs for high-severity alerts and ensure rapid host quarantine/isolation — the 58-hour delay was the decisive failure
- Hunt for and block Qakbot, SystemBC, Cobalt Strike, rclone and BloodHound activity across the estate
- Block known Black Basta C2 domains and IPs at the perimeter and DNS layer
Workarounds
- Segment Active Directory tiers and limit lateral SMB/RDP paths
- Apply LSASS protection (Credential Guard / RunAsPPL) to blunt Mimikatz credential theft
Longer-term hardening
- Implement tiered administration: prohibit domain admins from logging onto standard member servers (the exact weakness flagged in Capita's prior pentest)
- Deploy EDR with behavioral detection and ensure containment actions are evidenced and verified, not assumed
- Restrict and monitor rclone/WinSCP and other bulk data-transfer tooling; alert on large outbound transfers to cloud storage (e.g. Mega)
- Implement phishing-resistant MFA and disable macros/restrict execution of mark-of-the-web files
Weaknesses (CWE) in Capita Black Basta Ransomware Incident (March 2023)
Timeline of Capita Black Basta Ransomware Incident (March 2023)
- Black Basta ransomware-as-a-service first identified, operating a double-extortion model and frequently using Qakbot for initial access.
- Despite alerts referencing 'Threat Alert High,' 'Credential access,' and 'Lateral movement,' the compromised device was not quarantined; the high-severity alert went unactioned for over 58 hours, far exceeding the 1-hour SLA.
- Malicious file inadvertently downloaded onto a Capita employee device; a high-priority security alert was raised within ~10 minutes and some automated action taken.
- During the 58-hour window the attacker exploited the foothold, moved laterally, and compromised Active Directory domain-administrator credentials (aided by the absence of policy preventing domain admins logging onto member servers).
- Bulk data staging and exfiltration began using rclone with SystemBC tunneling.
- Nearly one terabyte of data exfiltrated from Capita systems.
- Capita publicly stated there was 'no evidence' of customer data compromise — contradicted by the ~1TB exfiltration.
- Black Basta deployed ransomware across Capita systems and reset all user passwords, locking staff out of the network.
- Breach affected more than 6 million individuals, including pension/staff records, criminal-records-check data, sexual orientation, political opinions, and biometric data.
- CISA/FBI published #StopRansomware: Black Basta advisory (AA24-131A) documenting affiliate TTPs and IOCs; updated 8 November 2024.
- UK ICO fined Capita £14 million (£8M Capita plc + £6M Capita Pension Solutions) — its largest fine in a ransomware case — settled for under a third of the initially signalled £45M.
Sources cited for Capita Black Basta Ransomware Incident (March 2023)
- What organisations can learn from the record-breaking fine over Capita's ransomware incident
- Capita fined £14m for data breach affecting over 6m people
- ICO fines Capita £14m after ransomware caused major data breach
- Capita given record £14 million fine over ransomware attack security failings
- #StopRansomware: Black Basta (CISA AA24-131A)
- Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike
- Black Basta — Technical Analysis (Kroll)
- Capita Cyber Security Breach – £14 Million Fine Issued (Mayer Brown)
Detection coverage for TL-2026-0767
As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0767 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.