Jump to content

Recommended Posts

Posted

So it this a genuine email from Capita, that somehow they have managed to send to thousands of people, exposing countless emails and also making the email look like a phishing scam at the same time. None of my schools get support direct from Capita either and have never received any previous emails from them.

 

crapita.PNG

Posted
Received this email as well today - didn't think that it was suspect as I had received emails from this address earlier in the day. Didn't realise that Capita had changed the way you log incidents for CRC until today, and when I logged a call, it came from the same email address.
Posted
So it this a genuine email from Capita, that somehow they have managed to send to thousands of people, exposing countless emails and also making the email look like a phishing scam at the same time. None of my schools get support direct from Capita either and have never received any previous emails from them.

 

[ATTACH=CONFIG]56425[/ATTACH]

 

Same. We aren't a customer of Capita, but our County Council are. We never get emails directly from Capita.

Posted (edited)

It's more likely anyone that has had an account, SupportNet, MyAccount etc so regardless of custom it's likely to be the majority of SIMS schools business managers, data/sims managers, IT teams etc.

 

I'm enjoying the irony of the popup about disclosing PII when you visit their forum article on this :D

https://support.capitasoftware.com/csm?id=community_question&sys_id=73ac59e0db2e8850bee14872ba9619c6

Edited by synaesthesia
Posted
Been told by my SSU, who apparently have spoken to Capita, that this is a dodgy scam email, and not from Capita! The plot thickens. Either the SSU are misinformed, or Capita are trying to disown this one.
Posted

The link in my email points to capitasoftware.com (and doesn't seem to go anywhere malicious), and came from capita.co.uk. The originating server was outbound13.service-now.com which seem to tie in.

 

I'm not seeing any evidence of a scam email. This looks entirely like a competence cessation incident.

Posted
The message failed SPF and DMARC. capita.co.uk does have a DMARC record (but with p=none). Not sure about DKIM as there's some ARC gubbins showing instead, which I'm not able to understand much of yet. That might go some to explain why some people's mail systems are slapping warnings on it.
Posted

Good afternoon,

 

 

This afternoon you would have received an email titled “Incident INC0017274 has been assigned to group DO NOT USE”. Please accept our apologies, as this was sent in error.

 

 

We are aware that email addresses were visible and we are addressing this as a Data Breach.

 

 

Please be assured that the email does not contain any malware and is not a result of malicious activity. May we ask that you please delete the email.

 

 

We are currently investigating the root cause with our Information Security Team and we will provide further feedback in due course.

 

 

Once again, we apologise for any inconvenience caused.

 

 

Kind regards

 

 

Will Baker

 

Head of Support Services

 

Education Software Solutions

  • Thanks 3
Posted
Good afternoon,

 

 

This afternoon you would have received an email titled “Incident INC0017274 has been assigned to group DO NOT USE”. Please accept our apologies, as this was sent in error.

 

 

...

 

When I saw this in my inbox I was shocked, It didn't have everyone's email in the To field!

  • Thanks 1
Posted

Just received the apology email!They are "investigating the root cause with our Information Security Team "

 

Security team ?! - how about the user which clicked the send button lol

Posted (edited)

And this is why when people ask for opinions on EDULink one for instance I laugh.

 

If your MIS is crap and not fulfilling you needs change your MIS ! dont stick a fancy front end on it and think you've fixed the issue.

 

The product is outdated and the company are absolutely clueless. The quicker their monopoly gets ripped apart the better. Unfortunately its seems to be a slow deliberate tear rather than the complete collapse their incompetence deserves.

 

*** bit of a rant but its been a long week already! ***

Edited by DODICT
Posted
And this is why when people ask for opinions on EDULink one for instance I laugh.

 

If your MIS is crap and not fulfilling you needs change your MIS ! dont stick a fancy front end on it and think you've fixed the issue.

 

The product is outdated and the company are absolutely clueless. The quicker their monopoly gets ripped apart the better. Unfortunately its seems to be a slow deliberate tear rather than the complete collapse their incompetence deserves.

 

*** bit of a rant but its been a long week already! ***

 

Maybe, but nothing's perfect - please don't tar Edulink's name in this one! Yes they effectively make money doing what Capita perhaps should (or do, sort of with various addons of their own) but you'd be hard pushed to find a single MIS system out there that ticks all the boxes without some help. It's not a one size fits all world. (Off topic though so let's keep this about this email)

Posted

We received this from Link2ICT about half an hour before Capita's official statement:

 

Dear Colleagues,

 

 

We have received news of a new phishing attack that is in circulation. The email comes from what appears to be a Capita email address requesting that schools take action regarding a bug in the SIMS system.

 

 

We have spoken with our SIMS colleagues and identified that this is a phishing email, as the reference number does not exist and our SIMS support team has not been notified of any issues.

 

 

Please do not respond to this email and delete it immediately. It has already been logged with our network security team but as we always advise, please be mindful of any emails that seem suspicious.If it seems wrong, it usually is.

 

 

Further Information:

If you have any questions, please contact the service deskfor more details.

 

 

Thanks in advance for your cooperation.

 

 

Link2ICT

I guess they hadn't had the update from Capita yet!

Posted
We received this from Link2ICT about half an hour before Capita's official statement:

 

 

I guess they hadn't had the update from Capita yet!

 

Neither had they bothered to take the time to investigate properly and made an assumption, therefore sending out emails before knowing facts. There's a fair bit of unprofessionalism coming out today.

Posted
Just received the apology email!They are "investigating the root cause with our Information Security Team "

 

Security team ?! - how about the user which clicked the send button lol

 

Speaking to the user wouldn’t be solving the root problem. They shouldn’t have been able to do this in the first place.

  • Thanks 1
Posted

Did anyone else get a reply all from a "Junior Service Desk" working at a support company that was included in the email from capita - with everyone's email in the To... field as well?

 

We have never done anything with that company, so would assume that that email would also be a data breach as everyone's email addresses were in the To... field!

Posted
Did anyone else get a reply all from a "Junior Service Desk" working at a support company that was included in the email from capita - with everyone's email in the To... field as well?

 

We have never done anything with that company, so would assume that that email would also be a data breach as everyone's email addresses were in the To... field!

 

If they were just replying to capita's email then I would say no.

Posted
Speaking to the user wouldn’t be solving the root problem. They shouldn’t have been able to do this in the first place.

 

It's not the best by any means, But I believe that its the standard way for ServiceNow when you generate a job and send a email out to multiple people so they can respond into it.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...