Capita hack: 90 organisations report data breaches to watchdog
bbc.com
bbc.com
Some of the data was listed for sale: https://www.theregister.com/2023/04/18/capita_breach_gets_wo...
For those not in the UK, Capita runs outsourced IT systems for lots of government agencies, councils, the NHS etc. Their nickname is "crapita" in some circles, due to how bad they can be.
It all started with an open AWS bucket...
It's possibly the worst software I have ever had the misfortune to interact with. It started as a Microsoft Access database, written by a teacher, was taken on by a council, and then expanded to be the largest MIS in the UK.
It has always been slow, refuses to cache data on the client side which results in data loss if your wifi signal switches off, has the most clumsy UX I've ever seen, and despite being a modern piece of software it makes Curses look like an advanced UI from the next millennium.
Hmmm - I don't have much faith in Experian's approach to securing personal information and only providing 12 months service is a joke. If a company (i.e. Capita) leaks information through their own lack of competence, then they should be required to indemnify the victims for as long as the data is relevant - in this case it would be however many decades until the people retire. If you're going to store private information that remains relevant for a long time, then there's a need for much greater responsibility in ensuring that it doesn't get leaked.