UK pension schemes reveal impact of cyber breach

A number of UK pension schemes and insurers, including the Unilever Pension Scheme and Rothesay, have confirmed that they have also been impacted by the recent Capita cyber incident.

As reported by our sister publication Pensions Age, Capita previously announced in April that it had experienced a cyber incident and that there was evidence of “limited data exfiltration from the small proportion of affected service estate which might include some customer, supplier or colleague data”.

Following Capita's investigations, a number of UK pension schemes have written to members to confirm that their personal details may have been affected by the recent incident, with The Pensions Regulator encouraging impacted trustees to proactively warn members about the potential for pension scams.

In particular, the Universities Superannuation Scheme (USS) revealed that the personal details of around 470,000 active, deferred and retired members may have been accessed during the recent Capita cyber incident, while the M&S Pension Scheme trustee said the security of personal data for a "large proportion" of its members may have been affected.

Following on from this, Rothesay has confirmed that the incident also affected the personal data of around 50,000 individuals who were former members and dependants of Telent’s GEC 1972 Plan and joined Rothesay in 2019.

The insurer emphasised that it is only these individuals who joined Rothesay in 2019 from Telent’s GEC 1972 Plan who are affected, with Capita having confirmed they are the only Rothesay policyholders impacted by its cyber incident.

All impacted individuals are being contacted by post by Rothesay to reassure them that their pension policies are unaffected and to provide further details and guidance on what steps they should take to protect their data.

In line with support offered by the USS trustee, Rothesay also confirmed that individuals who have been affected are being offered a specialist fraud monitoring service provided by Experian as a precaution, with membership to be paid in full at no cost to those impacted.

"Rothesay has been working very closely with Capita to understand how its cyber incident occurred and to put things right. Rothesay’s own systems were not impacted at all by the incident," the insurer stated.

"Protecting the data of the over 825,000 pensions we secure is a responsibility we take incredibly seriously. On behalf of Capita and Rothesay, we would like to offer our deepest apologies for any concern that this incident may have caused."

Unilever has also since confirmed that some of its member data may have been accessed by an unauthorised third party as part of the recent Capita cyber incident, with the trustee now contacting those members affected to make them aware.

Although the Unilever Pension Scheme emphasised that members' pension benefits are safe and unaffected by this incident, it also reminded members of the need to stay vigilant against unusual online activity or information requests.

Colchester City Council also said that it is taking “swift and decisive action” in response to the Capita cyber incident, revealing that the data breach has affected several other local authorities around the country, relating to historic data – the full extent of which is being investigated.

Colchester City Council chief operating officer, Richard Block, stated: “The council is extremely disappointed that such a serious and widespread data breach has occurred and is robustly addressing the matter with Capita.

"I want to reassure all residents that we are taking steps with Capita to fully understand how they have caused this data breach as well as any further action required.

“We understand that this issue will cause concern among residents and apologise to those affected on behalf of Capita.

"Our top priority is to safeguard the privacy and security of our residents' personal information, and we are taking swift and decisive action to investigate the situation and ensure Capita's processes are improved to avoid any future breaches.”

Commenting in relation to the cyber incident and affected clients, a Capita spokesperson said: “Capita continues to work closely with specialist advisers and forensic experts to investigate the incident and we have taken extensive steps to recover and secure the data.

“In line with our previous announcement, we are now informing those we have identified to be affected. We have worked quickly to provide our clients with information, reassurance and support, while delivering for them as a business. In instances where we need to provide further support to those affected, we will do so.”

    Share Story:

Recent Stories


Podcast: Stepping up to the challenge
In the latest European Pensions podcast, Natalie Tuck talks to PensionsEurope chair, Jerry Moriarty, about his new role and the European pension policy agenda

Podcast: The benefits of private equity in pension fund portfolios
The outbreak of the Covid-19 pandemic, in which stock markets have seen increased volatility, combined with global low interest rates has led to alternative asset classes rising in popularity. Private equity is one of the top runners in this category, and for good reason.

In this podcast, Munich Private Equity Partners Managing Director, Christopher Bär, chats to European Pensions Editor, Natalie Tuck, about the benefits private equity investments can bring to pension fund portfolios and the best approach to take.

Mitigating risk
BNP Paribas Asset Management’s head of pension solutions, Julien Halfon, discusses equity hedging with Laura Blows

Advertisement