# Capita Black Basta Ransomware Incident (March 2023) — Record £14M UK ICO Fine for 6M+ Affected Individuals

> In March 2023 the Black Basta ransomware group breached UK outsourcing giant Capita, gaining initial access via a Qakbot infection, deploying Cobalt Strike, SystemBC, rclone and BloodHound to compromise Active Directory and obtain domain-admin access, then exfiltrating nearly 1TB of data before detonating ransomware. A high-priority security alert went unactioned for over 58 hours. The UK ICO later issued a record £14 million ransomware-case fine (£8M against Capita plc, £6M against Capita Pension Solutions) over the breach of more than 6 million people's data.

- **Published:** 2026-06-10T00:00:00Z
- **Last reviewed:** 2026-06-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0767
- **ID:** TL-2026-0767
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** RESOLVED
- **Actor:** Black Basta
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 22 March 2023 a malicious file was inadvertently downloaded onto a Capita employee's device, initiating the intrusion that the UK Information Commissioner's Office (ICO) detailed across a 136-page penalty report. A high-priority security alert was raised within roughly 10 minutes and some automated action was taken, but Capita did not quarantine the compromised device for over 58 hours — a window that vastly exceeded the contractual 1-hour SLA for high-severity (P2) alerts and during which the attacker established a foothold, moved laterally, and accessed credentials. Alerts during this period reportedly carried terms such as 'Threat Alert High,' 'Credential access,' and 'Lateral movement.'

The intrusion follows the well-documented Black Basta affiliate playbook. Initial access was achieved through Qakbot (Qbot), which establishes backdoor access and is commonly used to stage SystemBC (a SOCKS5 proxy/C2 tunneling implant). Cobalt Strike was deployed for command-and-control, reconnaissance, and additional tooling delivery. BloodHound was used for Active Directory enumeration to map attack paths to privileged accounts. A prior Capita penetration test had explicitly flagged that 'there are no policies preventing domain admins logging onto standard member servers' — exactly the weakness that enabled lateral movement and domain-administrator credential compromise. With domain-admin control established, the actor used rclone (and SystemBC tunneling) to exfiltrate nearly one terabyte of data between 29 and 30 March 2023.

On 31 March 2023 Black Basta deployed ransomware across Capita systems and reset all user passwords, locking staff out of their network. The same day, Capita publicly stated there was 'no evidence' of customer data compromise — a claim contradicted by the ~1TB exfiltration. The stolen data affected more than 6 million individuals and included highly sensitive categories: pension and staff records, criminal-records-check data, sexual-orientation data, political opinions, and biometric information. In October 2025 the ICO announced a £14 million fine — its largest in any ransomware case — split as £8 million against Capita plc and £6 million against Capita Pension Solutions Limited, settled voluntarily for under a third of the £45M the regulator had initially signalled. The case is a landmark example of how SOC alert-handling failure (an unactioned high-severity alert) directly enabled a catastrophic data breach.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1133 External Remote Services
- T1547 Boot or Logon Autostart Execution
- T1078 Valid Accounts
- T1068 Exploitation for Privilege Escalation
- T1685 Disable or Modify Tools
- T1070 Indicator Removal
- T1003 OS Credential Dumping
- T1482 Domain Trust Discovery
- T1087 Account Discovery
- T1018 Remote System Discovery
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1071 Application Layer Protocol
- T1219 Remote Access Tools
- T1572 Protocol Tunneling
- T1567 Exfiltration Over Web Service
- T1048 Exfiltration Over Alternative Protocol
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1531 Account Access Removal

## Sources

- [What organisations can learn from the record-breaking fine over Capita's ransomware incident](https://doublepulsar.com/what-organisations-can-learn-from-the-record-breaking-fine-over-capitas-ransomware-incident-6afbdfcdd35b)
- [Capita fined £14m for data breach affecting over 6m people](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/10/capita-fined-14m-for-data-breach-affecting-over-6m-people/)
- [ICO fines Capita £14m after ransomware caused major data breach](https://www.computerweekly.com/news/366632591/ICO-fines-Capita-14m-after-ransomware-caused-major-data-breach)
- [Capita given record £14 million fine over ransomware attack security failings](https://therecord.media/capita-record-fine-uk-ico-ransomware-attack)
- [#StopRansomware: Black Basta (CISA AA24-131A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a)
- [Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike](https://www.trendmicro.com/en_us/research/22/j/black-basta-infiltrates-networks-via-qakbot-brute-ratel-and-coba.html)
- [Black Basta — Technical Analysis (Kroll)](https://www.kroll.com/en/publications/cyber/black-basta-technical-analysis)
- [Capita Cyber Security Breach – £14 Million Fine Issued (Mayer Brown)](https://www.mayerbrown.com/en/insights/publications/2025/10/capita-cyber-security-breach-14-million-pounds-fine-issued)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0767
