Planned maintenance: Please note EAPF Online will be unavailable between 09:00 on 30 October until 17:00 on 31 October 2019 for essential maintenance. We apologise for any inconvenience caused.

You will be aware that Capita experienced a cyber-attack in March 2023, where member data was exfiltrated.  Since then, a third-party expert has monitored the Dark Web daily for any trace of this data. Whilst the monitoring continues, there is no evidence of any data leak or misuse to date, nor is there evidence of the data being available illegally on any third-party websites.

We’ve continued to work with Capita and our professional advisor throughout to ensure data security measures are as robust as they can possibly be. This includes an assurance audit of Capita’s security measures by our professional advisor. The outcome of which confirmed that Capita’s processes are deemed to be ‘advanced’ in all aspects.

The final report states:

“Capita have a robust and effective security governance program, supported by an Information Security Management System (ISMS) and ISO 27001 certification. Furthermore, Capita utilise an extensive list of front-line security controls to accompany a well-established incident management and business continuity process for the organisation.”

This work will be on-going with Capita throughout their cyber transformation programme, so that we continually gain the highest level of assurance on the security and integrity of their systems.  We’ll also be utilising external advisers to support with this assurance, to always ensure best practice.

To date, the Information Commissioners’ Office (ICO) has yet to publish its adjudication of the incident, nor do we have any timeline. However, we acknowledge that such cyber investigations can take several years to complete (especially with several pension schemes involved and deeper complexities). We also acknowledge that Capita continue to engage with the ICO to fully support their investigation.

Your Experian membership will not be extended after it comes to an end in the coming months. If you wish to extend your membership at this time, at your own cost, more information about the options can be found under the 'Identity theft' section on the Experian website at www.experian.co.uk/consumer/which-product-is-right-for-me.html

We will continue to update the Cyber hub on our website with updates, including the Q&A document.

Cyber incident hub

Send message
Close