ACRO Criminal Records Office
Incident posture
Linked entities
- Victim
- ACRO Criminal Records Office
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A UK Criminal Records Office (ACRO) was issued a reprimand by the Information Commissioner's Office after a hacker gained unauthorized access to its website and content management system, exposing sensitive personal data of over 10,000 individuals. The compromised information included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal offence records, affecting victims of domestic violence and applicants for International Child Protection Certificates. The breach stemmed from poor patch management, as the responsible web development supplier failed to identify and apply required CMS security updates while ACRO provided no oversight of the process, compounded by unmonitored malware detection alerts from an existing security solution. Due to inadequate record keeping, it remains unclear whether the attacker actually exfiltrated any of the exposed data.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Between August 2022 and March 2023, an unauthorized actor gained access to the systems of the UK’s Criminal Records Office (ACRO), exploiting weaknesses in the agency’s web infrastructure to remain present on the network for an extended period. The intrusion affected the ACRO website and its content management system, identified in the investigation as Kentico. Because ACRO’s record keeping around the incident was poor, the agency could not determine with certainty whether the attacker actually exfiltrated data belonging to 10,920 individuals. The breach was eventually disclosed to the Information Commissioner’s Office, which opened an investigation and determined that the incident constituted an infringement of the UK General Data Protection Regulation. The reprimand issued by the ICO on 13 August 2026 was the formal outcome of that inquiry, and it was accompanied by a public statement identifying two principal security failings: inadequate patch management and insufficient security monitoring.
The data exposed in the incident was unusually sensitive. Compromised records included names, dates of birth, postal addresses, National Insurance numbers, passport details, driving licence information, bank account details, and biometric data. The breach also encompassed what the ICO described as “highly sensitive criminal offence and special category information.” Among the individuals affected were applicants connected to International Child Protection Certificates and victims of domestic violence, both groups considered particularly vulnerable to the consequences of identity exposure. After the incident became known, ACRO received dozens of complaints, reflecting the volume and personal nature of the records involved. The seriousness of the data at risk shaped both the regulatory response and the agency’s subsequent remedial programme.
The first technical failing identified by the ICO concerned the patching regime applied to ACRO’s website. The policing agency’s managed service provider was responsible for operating system updates, but the Kentico content management system sat outside that arrangement. Responsibility for patching the CMS fell to ACRO’s web development supplier, and that supplier was tasked with applying updates rather than identifying when they were required. ACRO itself did not monitor for available security patches, leaving a gap in oversight over a critical control. The attacker is reported to have exploited this gap to gain and maintain unauthorized access to the website and its underlying CMS over several months.
The second failing concerned the operation of ACRO’s security monitoring tools. The agency had a Trend Micro solution in place intended to detect and quarantine malware. Although the product generated alerts when malicious activity was identified, those alerts were not reviewed or acted upon by ACRO staff. The ICO noted that, had the alerts been investigated at the time and an appropriate response been conducted, further malicious activity would likely have been prevented. The combination of an unpatched CMS and unmonitored security alerts allowed the intrusion to continue undetected throughout the seven-month window described in the investigation.
When ACRO did respond to the incident, it took a series of significant remediation steps. The compromised infrastructure was decommissioned, and services were migrated to alternative platforms. The agency implemented additional security monitoring, improved its visibility of cyber threats, and strengthened network segmentation that had already been in place and which the ICO acknowledged had reduced the blast radius of the attack. These actions were cited by the regulator as factors that mitigated what could otherwise have been a more severe outcome, and contributed to the ICO’s decision to issue a reprimand rather than a financial penalty. The public sector approach taken by the ICO, which limits the financial penalties it can levy on government bodies, also shaped the regulatory outcome.
The reprimand was issued alongside public comments from the ICO’s group manager for civil and cyber investigations, Jonathan Balmforth, who emphasized the importance of clear accountability for security updates and effective monitoring of warning signs. The ICO framed the case as an illustration of the need for both the right technology and the right policies, responsibilities, and oversight arrangements. The confirmed scope of the incident, drawn from the ICO’s published findings, comprises 10,920 affected individuals, the August 2022 to March 2023 intrusion window, the Kentico CMS and website as the compromised systems, and the categories of personal and special category data exposed.
Sources
Sources available to members: 1 source.