logo

What organisations can learn from the record breaking fine over Capita’s ransomware incident

ID: b9ab8ed7-dd09-51b3-a587-27dbae88449f

STIX ID: report--b9ab8ed7-dd09-51b3-a587-27dbae88449f

Feed Name: DoublePulsar

Threat Score
80/100

Date Published: 2025-11-20

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

**Executive summary:** The report analyzes Capita’s Black Basta ransomware incident and subsequent ICO judgement, detailing Qakbot initial access, exfiltration of about six million people's records using SystemBC/rclone, use of BloodHound for AD reconnaissance and privilege escalation, extensive SOC failures (missed P2 alerts, understaffing, SLA breaches), and the resulting £14m fine as lessons for detection, containment, and governance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.