ACRO Criminal Records Office: Three intrusions at UK criminal records office went undetected for two years

ACRO Criminal Records Office: Three intrusions at UK criminal records office went undetected for two years

UK Criminal Records Office Reprimanded After Repeated Cyber Breaches Expose Sensitive Data

The UK’s Information Commissioner’s Office (ICO) has formally reprimanded the ACRO Criminal Records Office a national policing unit handling sensitive data on the Police National Computer following a series of cyberattacks between July 2021 and June 2023 that exposed personal information, including that of domestic violence victims.

The breaches stemmed from systemic security failures, including unpatched vulnerabilities in ACRO’s public-facing customer portal, which ran on an outdated version of the Kentico content management system (CMS) since September 2019. Despite known security flaws and available patches, neither ACRO nor its managed service providers applied updates, as responsibilities for maintenance were unclear.

Security alerts were also ignored. Trend Micro’s antivirus software flagged multiple threats, including attempts to deploy the Mimikatz credential-harvesting tool, but no action was taken due to undefined processes for handling such warnings. The ICO concluded that responding to these alerts could have prevented further malicious activity.

Forensic investigations identified three distinct incidents, labeled Group A, B, and C, though it remains unclear whether they were linked to the same threat actor. The most severe, Group A, involved persistent access to ACRO’s systems from August 2022 to March 2023, during which attackers staged nearly 11,000 records for potential exfiltration. However, ACRO’s insufficient logging left it unable to confirm whether data was actually stolen.

Another incident involved an SQL injection attack that exposed employee credentials. While the Medusa ransomware group later claimed responsibility, no stolen data appeared on its leak site, leaving questions about whether a ransom was paid or the claim was fabricated.

ACRO initially downplayed the breaches as "essential maintenance" before disclosing the incident in April 2023 after media inquiries. As a precaution, it notified over 84,000 individuals who had submitted applications during the at-risk period, though the ICO did not investigate the resulting complaints.

The ICO’s reprimand issued without financial penalties highlighted network segmentation as a mitigating factor, preventing attackers from accessing the core policing system. ACRO has since decommissioned the compromised infrastructure, implemented a new security monitoring system, and taken its old website offline. The regulator attributed the failures to institutional shortcomings rather than individual negligence.

Source: https://therecord.media/uk-criminal-records-office-acro-data-breaches?ref=tetmo.com

ACRO Criminal Records Office cybersecurity rating report: https://www.rankiteo.com/company/acro-criminal-records-office

"id": "ACR1787050668",
"linkid": "acro-criminal-records-office",
"type": "Breach",
"date": "7/2021",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '84,000+ individuals',
                        'industry': 'Law Enforcement',
                        'location': 'United Kingdom',
                        'name': 'ACRO Criminal Records Office',
                        'type': 'Government/Policing Unit'}],
 'attack_vector': ['Unpatched Vulnerabilities', 'SQL Injection'],
 'customer_advisories': 'Notified over 84,000 individuals who submitted '
                        'applications during the at-risk period',
 'data_breach': {'data_exfiltration': 'Unconfirmed (insufficient logging)',
                 'number_of_records_exposed': 'Nearly 11,000 records staged '
                                              'for exfiltration (unconfirmed '
                                              'if stolen)',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (PII, law enforcement data)',
                 'type_of_data_compromised': ['Personal information',
                                              "Domestic violence victims' data",
                                              'Employee credentials']},
 'date_publicly_disclosed': '2023-04',
 'description': 'The UK’s Information Commissioner’s Office (ICO) has formally '
                'reprimanded the ACRO Criminal Records Office following a '
                'series of cyberattacks between July 2021 and June 2023 that '
                'exposed personal information, including that of domestic '
                'violence victims. The breaches stemmed from systemic security '
                'failures, including unpatched vulnerabilities in ACRO’s '
                'public-facing customer portal and ignored security alerts.',
 'impact': {'brand_reputation_impact': 'Yes (formal reprimand by ICO)',
            'data_compromised': 'Personal information, including domestic '
                                "violence victims' data",
            'identity_theft_risk': 'Yes (PII exposed)',
            'operational_impact': 'Decommissioned compromised infrastructure, '
                                  'took old website offline',
            'systems_affected': ['Public-facing customer portal',
                                 'Employee credentials']},
 'investigation_status': 'Completed (ICO reprimand issued)',
 'lessons_learned': 'Systemic security failures due to unclear maintenance '
                    'responsibilities, ignored security alerts, and '
                    'insufficient logging. Network segmentation helped '
                    'mitigate further damage.',
 'post_incident_analysis': {'corrective_actions': ['Decommissioned compromised '
                                                   'infrastructure',
                                                   'Implemented new security '
                                                   'monitoring system',
                                                   'Took old website offline'],
                            'root_causes': ['Unpatched vulnerabilities in '
                                            'Kentico CMS (since September '
                                            '2019)',
                                            'Ignored security alerts (Trend '
                                            'Micro antivirus)',
                                            'Undefined processes for handling '
                                            'security warnings',
                                            'Insufficient logging to confirm '
                                            'data exfiltration']},
 'ransomware': {'ransomware_strain': 'Medusa (claimed, but no data leaked)'},
 'recommendations': ['Apply security patches promptly',
                     'Define clear processes for handling security alerts',
                     'Improve logging and monitoring capabilities',
                     'Clarify maintenance responsibilities with managed '
                     'service providers'],
 'references': [{'source': 'Information Commissioner’s Office (ICO)'}],
 'regulatory_compliance': {'fines_imposed': 'None (formal reprimand only)',
                           'regulatory_notifications': 'ICO reprimand issued'},
 'response': {'communication_strategy': "Initially downplayed as 'essential "
                                        "maintenance'; later disclosed after "
                                        'media inquiries',
              'containment_measures': ['Decommissioned compromised '
                                       'infrastructure',
                                       'Took old website offline'],
              'enhanced_monitoring': 'Yes (new security monitoring system '
                                     'implemented)',
              'network_segmentation': 'Yes (mitigated further access to core '
                                      'policing system)',
              'remediation_measures': ['Implemented new security monitoring '
                                       'system',
                                       'Applied patches (post-incident)']},
 'threat_actor': ['Unknown (possibly Medusa ransomware group)'],
 'title': 'UK Criminal Records Office Reprimanded After Repeated Cyber '
          'Breaches Expose Sensitive Data',
 'type': ['Data Breach', 'Cyberattack'],
 'vulnerability_exploited': 'Outdated Kentico CMS (unpatched since September '
                            '2019)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.