Capita Cyber Incident update

17 October 2025

In March 2023 Capita, who provide our pension administration services, experienced a cyber incident. The incident predominantly affected the security of some personal data relating to members who were receiving their pension from the Scheme.

The Trustee takes the responsibility of protecting member data very seriously. The Trustee, with the support of AXA UK, has, since it first became aware of the cyber incident, continued to work closely with Capita to review and improve the systems and processes which Capita has in place from a cyber security perspective. This has involved a number of activities, including the AXA UK Security Team assisting the Trustee with an evidence-based security assessment of Capita’s technical and organisational controls.

On 15 October 2025, the Information Commissioner's Office (“ICO”) issued a penalty notice to Capita in relation to the 2023 cyber incident. For clarity, there have been no new developments in relation to the cyber incident itself in terms of the data that was impacted. The ICO's investigation made a number of findings, including that, in 2023, Capita had failed to implement appropriate technical and organisational measures to safeguard the data they held. 

The ICO's penalty notice states that Capita, aided by Microsoft, has since made a number of significant improvements to security following the cyber incident. The ICO also notes that Capita has since put in place much more robust systems and has doubled the number of Security Operations Centre analysts at Capita's disposal to deal with cyber security threats. 

The Trustee is reviewing the penalty notice issued to Capita, and will take the ICO's conclusions into consideration in determining whether any further steps are required.

As previously communicated, Capita has told the Trustee that it has no evidence that any of the information impacted as a result of the 2023 incident has been misused or made available illegally. In addition, AXA UK's Business Security Team has been conducting its own checks and has no reason to believe that the information is on the dark web.

Cyber security suggestions

We would remind all our members to remain extra vigilant for unusual activity on their accounts, including suspected phishing emails, and other potential scams and/or fraudulent activity. Have a look at the Government National Cyber Security Centre's guidance on data breaches. The FCA also has some useful information on how to spot the warning signs of financial scams here.

Please remember:

  • If you receive an unsolicited call or other contact from someone, only give out your personal information if you are happy that the person contacting you is who they say they are.
  • Be careful with unexpected emails or texts, especially if they ask you to click on a link or enter your login details or passwords.
  • Check your bank statements for any signs of unusual activity and consider checking for any new credit files or credit searches in your name which you don't recognise.
  • If in doubt – stop and think. Hang up or end the conversation if you need to. Contact your bank or financial services provider directly if you aren't sure. If you have any suspicions at all, please don't give out any information or bank details. Just hang up or delete the worrying text or email.

If you have any concerns, please consider contacting your bank, in order that as a minimum they can put an appropriate note on their records. Your bank may also be able to help you with other steps you can take to help protect your account, such as changing PIN numbers, security questions or passwords and reviewing direct debits, standing orders and other payments in and out of your account.

Here are some other suggestions that may help you protect yourself and your information against scammers:

  • Protect your email with a strong password (tip: use 3 random words to create a single password that’s difficult to crack).
  • Do not share your password with anyone.
  • Install the latest security updates to your browser software and personal computing devices.
  • If in doubt, do not open emails from senders you do not recognise.
  • Check links look correct before you click on them.
  • Be suspicious of anyone who asks for your bank account or credit card details.
  • If the email contains spelling mistakes, this can be a sign that this is a phishing scam. Do not open the email or attachments.
  • If you think you have been a victim of fraud you should report it to Action Fraud, the UK's national fraud and internet crime reporting centre, on 0300 123 2040.

We’ve updated the FAQ document we prepared previously which you may find useful.

If you have any questions regarding the cyber incident, please contact Capita at cyberqueries_all@capita.com or 0800 229 4005 (Monday to Friday – 08.30am to 5.30pm).

The AXA Pensions Team is available (at pensiontrustees.uk@axa-uk.co.uk); however, we would ask if you can contact Capita in the first instance.

Back
Close