Skip to content
City PM
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
Thursday 25 May 2023 4:57 pm  |  Updated:  Thursday 25 May 2023 5:06 pm

Capita wins £565m in government contracts – despite major data breach

By: Lucy Kenningham

Add as a preferred source on Google

Capita was today confirmed as the government’s chosen partner in two contracts worth a combined total of £565m – despite two recent major data breaches, the impact of which is still being investigated.

The firm said the investigation and clear up will cost between £15m and £20m – this includes “further steps [taken] to ensure the integrity, safety and security of its IT infrastructure”.

The data and IT outsourcing giant will deliver a new service – the Functional Assessment Services – for the Department for Work and Pensions (DwP) and the Department for Communities (DfC) in Northern Ireland, which will entail carrying out health assessments for vulnerable members of society such as benefits claimants.

Chief executive Jon Lewis said Capita “focus[es] on quality and claimant experience” and that the firm will invest in “our health professionals who deliver such a vital public service”.

Capita is one of the UK government’s biggest suppliers, handling government contracts, private pension plans and providing services to local government including administration around benefits and taxes.

However, the firm has recently suffered two major data breaches. The first, in late March, was a cyber attack. Although the data processing firm originally said there was “no evidence” of comprised customer data, it later emerged that private sector clients, including M&S, Diageo, Unilever and Rothesay, all likely had members affected by the hack.

The second data breach emerged this month and has affected local councils working with Capita.

The news was sparked by Colchester council last Monday, which said benefits details of its residents were left exposed on an unsecured Amazon Data Bucket that was controlled by Capita.

Several other councils have now complained of similar breaches and are launching investigations.

Read more

Professional services firms the ‘flavour of the month’ for cyberattacks

The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”

​​Coventry council said it had “been belatedly informed that there has been a potential historic data breach by our financial services contractor Capita”.

When asked by City PM about the new contracts and the data breach, the DwP said “an evaluation process was undertaken, which evaluated bids based on a combination of quality and pricing to achieve the most economically advantageous tender for each geographical area”.

Capita declined to comment further but has previously said it is working with “third-party technical advisers to investigate” the latest revelation of a data breach involving local councils. It confirmed historic data is “secure and no longer accessible”.

In a statement announcing the new contracts, Lewis, said: “We are proud to have been selected as the preferred bidder to deliver these new contracts, which are central to the government’s long-term plan for health assessments.

“We will bring our strong track record for delivery in this sector and our relentless focus on quality and claimant experience to this range of benefits. We will also be investing in our health professionals who deliver such a vital public service.”

The news comes as the public body the Information Commissioner’s Office (ICO) issued a statement on Capita’s double data breach: “We are aware of two incidents concerning Capita, regarding a cyber-attack in March and the use of publicly accessible storage”.

The IPO recognised the number of complainants concerning Capita: “We are receiving a large number of reports from organisations directly affected by these incidents and we are currently making enquiries.”

It also reconfirmed that “organisations must notify the within 72 hours of becoming aware of a personal data breach, unless it does not pose a risk to people’s rights and freedoms.

“If an organisation decides that a breach doesn’t need to be reported, they should keep their own record of it and be able to explain why it wasn’t reported if necessary.”

Read more

UK economy falters as deeper damage to growth to come

Rachel Reeves speaking at an IOD event.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

Related Topics

  • Capita

Trending Articles

  • Top Burnham adviser calls for capital gains and inheritance tax hikes

  • Clarkson’s Farm and why businesses must stop blaming the weather

  • Two solicitors linked to Post Office scandal charged with misconduct

  • Lloyd’s deputy chair: The City is a club in the best sense

  • A meeting with the breakfast king of Mayfair

More from City PM

  • Professional services firms the ‘flavour of the month’ for cyberattacks

    Prof Services
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • UK economy falters as deeper damage to growth to come

    Economics
    Rachel Reeves speaking at an IOD event.
  • SpaceX kicks off bond sale as it looks to begin mass borrowing spree

    Markets
    Elon Musk discussing SpaceX investment as Scottish Mortgages largest holding on a business news platform
  • Luminance’s boss: Why building our own AI beats ‘rented intelligence’

    Legal
    Unfortunately, I dont have the specifics of the article content or title to generate the alt text. Could you provide more ...
  • When AI’s taken all the work, what will we all do?

    Opinion
    Wall-E robot character in futuristic setting showcasing advanced robotics technology and innovation
  • Balfour Beatty emerges from US oversight scheme after fraud against military

    Transport & Infrastructure
    Balfour Beatty construction site showcasing cranes, workers, and building progress against a city skyline backdrop
  • Social media ban may push children to ‘darker corners of the internet,’ lawyers warn

    Legal
    Australia's policy, which came into force in December and bars children under 16 from major platforms including Tiktok, Instagram, Snapchat and X.
  • Ditched by clients and Australian government: What is happening down under at KPMG?

    Big Four
    KPMG Australia office building exterior with modern glass architecture and corporate signage in a bustling business district.

City PM — European politics, business and analysis.

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Topics

  • Business
  • Markets
  • AI
  • Technology
  • Opinion
  • Energy

More

  • Politics
  • Economics
  • Fintech
  • Legal
  • Sport
  • Life

Company

  • About City PM
  • Editorial Policy
  • Corrections
  • Contact
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 City PM · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
About · Editorial Policy · Corrections · Contact · Privacy