A USS member never chose Capita. USS did. The accountability did not transfer with the outsourcing.
USS is the data controller. Capita was the processor USS selected. The intrusion failures were Capita's, documented by the ICO, and they are exactly what USS became answerable for by choosing that processor. Accountability follows the relationship, not the contract.
Free case file, Capita and USS Hartlink pension breach, 2023
Two clocks
The failure was a timing failure, and the remedy is a timing mismatch. So this case is told in time, not in attacker moves. Poor controls, then a remedy that expires while the harm does not.
Clock 1The intrusion clock
The gap between when the defence knew and when it acted. The alarm sounded in ten minutes. The response came 58 hours later.
22 Mar 202331 Mar 2023
Initial accessHour 0, malicious file on a device.
Alert, +10 minThe defence knew.
Domain admin+4.5 h, backupadmin reached.
Quarantined+58 h, against a 1 h target.
ExfiltrationNearly 1 TB, 29 to 30 Mar.
Realised, day 9Ransomware, all passwords reset.
Target response against actual response
Drawn to the same scale. The actual response bar is 58 times the target.
1 hourtarget response
1 h
58 hoursactual response
58 h to quarantine
Flagged as a known weakness three times, never fixed. The missing admin tiering model was raised on at least three separate occasions.
Clock 2The exposure clock
What was stolen is permanent. The remedy offered was not. A National Insurance number cannot be reissued. The monitoring that protected it lasted twelve months.
What was stolen, USS membersno end date
Permanent identifiers exposed
→
Title, initials, name, retirement date, USS member number, and the two that cannot be reissued, National Insurance number and date of birth. These do not expire.
The remedy offeredends at 12 months
12 mo
Experian credit monitoring
ends
Twelve months of member-activated Experian Identity Plus monitoring, with an enrol-by deadline. The bar stops. The exposure above does not.
6,024,221
people had data exfiltrated. Capita forensic figure, cited by ICO.
~1 TB
exfiltrated, 29 to 30 March 2023.
58 h
to quarantine, against a 1 hour target.
4.5 h
from initial access to domain admin.
9 days
total dwell before the breach was realised.
£14m
ICO fine, reduced from a proposed £45m.
325
of 600 plus pension scheme organisations affected.
12 mo
monitoring, against permanent identifier exposure.
The chain, for context
Stage 1
Data placed at the processor. Hartlink files held separately on Capita servers.
T1591
Stage 2
One malicious file, one employee device.
T1566 / T1204
Stage 3
Domain administrator in under five hours. backupadmin, no admin tiering.
T1078 / T1550
Stage 4
Nine days and a silent SOC. Understaffed, below target 6 months prior.
T1069 / T1213
Stage 5
Almost a terabyte leaves.
T1567
Stage 6
Ransomware, the fine, and a mismatched remedy.
T1486 / T1531
Bridges to the modelled path Third-Party and Supply Chain Compromise, drill third-party and supply chain compromise. Crown reached, Customer PII and Domain Controllers.
Four failure points
The ICO's named failings, each shown with the control that answers it.
Failure
No admin tiering
Flagged 3 times, left unremedied.
Fix
Tier and isolate admin accounts so one foothold cannot reach domain admin.
TP-TIER, ID-PAM
Failure
58 hour response to a 10 minute alert
SOC understaffed 6 months prior.
Fix
Answer inside the hour, with automatic quarantine on a high priority alert.
OPS-SIEM, EP-EDR
Failure
Blind outsourcing
The processor's estate was not treated as in scope.
Fix
Treat the processor's estate as your own attack surface. The ICO points controllers to check controller and processor agreements.
TP-INV, TP-TIER
Failure
Remedy mismatched to harm
12 months against permanent exposure.
Fix
Match the remedy to permanent exposure. Cifas protective registration, proactive not opt-in enrolment, guidance beyond 12 months.
Remedy design
A note on the data. This reconstruction uses only the categories of data involved and the structure of the remedy. It contains no individual's name, National Insurance number, member number, retirement date, or activation code. No customer data is shown.
Sources. ICO penalty statement, 15 October 2025. ICO monetary penalty notice. USS member notification letter, May 2023. USS Capita incident hub. Kevin Beaumont, DoublePulsar. BushidoToken. BleepingComputer, 21 April 2023. The Guardian, 30 May 2023. Computer Weekly.
Every intrusion figure is cited to the ICO. The member field list and the remedy are cited to USS. Qakbot delivery and Black Basta involvement are reported or claimed, not ICO confirmed, and are labelled as such.