Theregister Capita's Civil Service Pension Portal Data Breach Exposes Member Information
Article Content
- •Capita's data breach affected 138 members of the Civil Service Pension Scheme.
- •The breach exposed personal data for about 35 minutes on March 30, 2026.
- •The Cabinet Office is assessing the situation and may take further action.
On March 30, 2026, Capita reported a data breach affecting its Civil Service Pension Scheme (CSPS) member portal, which exposed the personal data of 138 public sector workers for approximately 35 minutes. The breach allowed some members to access Annual Benefit Statements (ABS) that did not belong to them. Capita immediately suspended the ABS functionality and initiated an investigation into the incident. All affected members were notified by April 3, 2026. The Cabinet Office is closely monitoring the situation and may take further action. This incident marks Capita's second data breach in three years, raising concerns about its capability to manage the pension scheme effectively. The Public and Commercial Services Union (PCS) criticized Capita's handling of the situation, emphasizing the need for the government to consider insourcing the service. The breach comes amid ongoing issues with the pension portal's functionality and a significant backlog of cases inherited by Capita.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Capita in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…