Capita's Civil Service Pension Portal Data Breach Exposes Member Information
Severity: Low (Score: 36.9)
Sources: Databreaches, Computerweekly, Theregister
Summary
On March 30, 2026, Capita reported a data breach affecting its Civil Service Pension Scheme (CSPS) member portal, which exposed the personal data of 138 public sector workers for approximately 35 minutes. The breach allowed some members to access Annual Benefit Statements (ABS) that did not belong to them. Capita immediately suspended the ABS functionality and initiated an investigation into the incident. All affected members were notified by April 3, 2026. The Cabinet Office is closely monitoring the situation and may take further action. This incident marks Capita's second data breach in three years, raising concerns about its capability to manage the pension scheme effectively. The Public and Commercial Services Union (PCS) criticized Capita's handling of the situation, emphasizing the need for the government to consider insourcing the service. The breach comes amid ongoing issues with the pension portal's functionality and a significant backlog of cases inherited by Capita. Key Points: • Capita's data breach affected 138 members of the Civil Service Pension Scheme. • The breach exposed personal data for about 35 minutes on March 30, 2026. • The Cabinet Office is assessing the situation and may take further action.
Key Entities
- Data Breach (attack_type)
- Capita (company)
- Civil Service Pension Scheme (company)
- Civil Service Pensions Scheme (company)
- Government (industry)