UK Criminal Records Office ACRO Faces Reprimand After Prolonged Cybersecurity Breach
The UK’s Criminal Records Office (ACRO) received a regulatory reprimand from the Information Commissioner’s Office (ICO) after security failures exposed highly sensitive data belonging to nearly 11,000 individuals. The breach, disclosed in April 2023, involved persistent unauthorized access to ACRO’s website and Kentico content management system (CMS) for over seven months from August 5, 2022, to March 14, 2023.
The ICO’s investigation revealed that ACRO had run an unpatched version of Kentico CMS (v12.0.0) from September 2019 until March 2023, leaving known vulnerabilities unaddressed. Poor communication between ACRO and its managed service provider led to missed patches, as the supplier only learned in February 2020 that it was responsible for security updates. ACRO also lacked documented patching policies and failed to monitor Trend Micro antivirus alerts, which went unread due to unclear accountability.
Attackers staged sensitive data for potential exfiltration between February 15–16, 2023, including police certificate applications, subject access request forms, names, dates of birth, addresses, National Insurance numbers, passport and driving license details, bank account information, biometric data, and highly sensitive criminal offense records. While ACRO initially notified 84,048 individuals, investigators later determined that only 10,920 were directly affected. Complaints cited concerns over identity theft and financial risks, particularly from victims of domestic violence.
Despite the severity, ACRO avoided a fine due to network segmentation, which contained the breach to the CMS. Since discovery, ACRO has decommissioned the compromised infrastructure, implemented a SIEM system, improved monitoring, and migrated to Salesforce Experience Cloud. The ICO emphasized the need for clear accountability in patch management and proactive threat detection, while ACRO acknowledged the findings and committed to stronger data protection measures.
ACRO Criminal Records Office cybersecurity rating report: https://www.rankiteo.com/company/acro-criminal-records-office
"id": "ACR1786544859",
"linkid": "acro-criminal-records-office",
"type": "Breach",
"date": "8/2022",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '10,920',
'industry': 'Law Enforcement / Public Sector',
'location': 'United Kingdom',
'name': 'ACRO (UK Criminal Records Office)',
'type': 'Government Agency'}],
'attack_vector': 'Exploitation of unpatched vulnerabilities in Kentico CMS',
'customer_advisories': 'Initial notification to 84,048 individuals (later '
'corrected to 10,920 affected)',
'data_breach': {'data_exfiltration': 'Staged for potential exfiltration '
'(February 15–16, 2023)',
'number_of_records_exposed': '10,920',
'personally_identifiable_information': 'Names, dates of '
'birth, addresses, '
'National Insurance '
'numbers, passport and '
'driving license '
'details',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally identifiable '
'information',
'Financial information',
'Biometric data',
'Criminal offense records']},
'date_detected': '2023-03-14',
'date_publicly_disclosed': '2023-04',
'description': 'The UK’s Criminal Records Office (ACRO) received a regulatory '
'reprimand from the Information Commissioner’s Office (ICO) '
'after security failures exposed highly sensitive data '
'belonging to nearly 11,000 individuals. The breach involved '
'persistent unauthorized access to ACRO’s website and Kentico '
'content management system (CMS) for over seven months.',
'impact': {'brand_reputation_impact': 'Regulatory reprimand, negative '
'publicity',
'customer_complaints': 'Concerns over identity theft and financial '
'risks, particularly from victims of '
'domestic violence',
'data_compromised': 'Police certificate applications, subject '
'access request forms, names, dates of birth, '
'addresses, National Insurance numbers, '
'passport and driving license details, bank '
'account information, biometric data, and '
'highly sensitive criminal offense records',
'identity_theft_risk': 'High',
'operational_impact': 'Decommissioning of compromised '
'infrastructure, migration to Salesforce '
'Experience Cloud',
'payment_information_risk': 'High',
'systems_affected': 'Kentico CMS, website'},
'investigation_status': 'Completed',
'lessons_learned': 'Need for clear accountability in patch management, '
'proactive threat detection, and documented patching '
'policies. Importance of communication between '
'organizations and managed service providers.',
'post_incident_analysis': {'corrective_actions': 'Decommissioned compromised '
'infrastructure, implemented '
'SIEM system, improved '
'monitoring, migrated to '
'Salesforce Experience '
'Cloud, committed to '
'stronger data protection '
'measures',
'root_causes': 'Unpatched Kentico CMS (v12.0.0), '
'poor communication with managed '
'service provider, lack of '
'documented patching policies, '
'unmonitored antivirus alerts'},
'recommendations': 'Implement documented patching policies, improve '
'monitoring and alert systems, ensure clear accountability '
'for security updates, and enhance communication with '
'third-party providers.',
'references': [{'source': 'Information Commissioner’s Office (ICO)'}],
'regulatory_compliance': {'fines_imposed': 'None (reprimand issued)',
'regulations_violated': ['UK Data Protection Act '
'2018',
'GDPR'],
'regulatory_notifications': 'ICO investigation'},
'response': {'containment_measures': 'Network segmentation to contain the '
'breach to the CMS',
'enhanced_monitoring': 'Implemented SIEM system, improved '
'monitoring',
'network_segmentation': 'Yes',
'remediation_measures': 'Decommissioned compromised '
'infrastructure, implemented SIEM '
'system, improved monitoring, migrated '
'to Salesforce Experience Cloud'},
'title': 'UK Criminal Records Office ACRO Faces Reprimand After Prolonged '
'Cybersecurity Breach',
'type': 'Data Breach',
'vulnerability_exploited': 'Unpatched Kentico CMS (v12.0.0) with known '
'vulnerabilities'}