Capita PLC (LSE:CPI) has confirmed that the cyberattack it reported on 3 April resulted in data on staff, customers and suppliers being stolen by the hackers.
A Sunday Times report claimed that personal bank account details, passport photos and addresses had been leaked online and were available to buy following the attack.
“There is currently some evidence of limited data exfiltration from the small proportion of affected server estate which might include customer, supplier or colleague data,” said a statement today from the outsourcing group.
Capita had previously claimed that people’s personal details had remained secure.
In today’s statement, Capita also revealed that around 4% of its servers were affected by the hack, reportedly carried out by Russian group Black Basta.
The FTSE 250 group said it had taken nine days to realise it was under attack and to put a halt to it.
“From our investigations to date, it appears that the incident arose following initial unauthorised access on or around 22 March and was interrupted by Capita on 31 March,” its statement said.
The attack came through the company’s internal Microsoft 365 applications (Outlook, Office, Word etc) with most of its client services unaffected, Capita said.
“Virtually” all clients that were affected have had services restored, according to the company.