logo

Lessons from the BlackBasta Ransomware Attack on Capita

ID: 4cf3c2f6-20d0-57a3-8459-92dbff4eb43d

STIX ID: report--4cf3c2f6-20d0-57a3-8459-92dbff4eb43d

Feed Name: BushidoToken Blog

Threat Score
85/100

Date Published: 2025-10-19

Date Updated: 2026-05-08

...
...

This CTI report reviews the March 2023 BlackBasta ransomware attack on Capita that resulted in exfiltration of approximately 6,024,221 data subjects' records (including passports, NI numbers, bank details and biometrics), widespread domain compromise across at least eight domains, attempted ransomware deployment to over 1,000 hosts, an ICO fine of £14M and remediation costs up to £20M; the report reconstructs the timeline and TTPs, highlights root causes (missed/high-priority alerts, SOC understaffing, lack of AD tiering and automation), and provides actionable lessons (PAM, SOAR, AD segmentation, prompt remediation of pentest findings) for SOCs and CISOs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.