Ethical Hacking News
Exposing Critical Vulnerabilities: The UK Criminal Records Office Data Breach reveals how a critical vulnerability in ACRO's website and content management system allowed attackers to maintain persistent access for over seven months, exposing sensitive data of nearly 11,000 individuals.
ACRO's criminal records office exposed due to poor security measures. 11,000 people affected by data leak, with 10,920 potentially targeted. ICO reprimanded ACRO for failing to address basic cybersecurity failings. Attackers maintained access to ACRO's website and CMS for over 7 months. Lack of clear policies, responsibilities, and oversight arrangements contributed to vulnerability. Improvements made by ACRO since the attack, including decommissioning compromised infrastructure and implementing a SIEM system.
The United Kingdom's criminal records office, ACRO, has been exposed for its woeful security measures that led to a sensitive data leak affecting nearly 11,000 people. The Information Commissioner's Office (ICO) has reprimanded ACRO rather than imposing a financial penalty, citing the organization's failure to address basic cybersecurity failings.
In April 2023, ACRO disclosed a "cybersecurity incident" but claimed that no evidence suggested any data was compromised. However, an investigation by the ICO revealed that attackers maintained persistent access to ACRO's website and content management system for over seven months, staging sensitive data for possible exfiltration. The breach was uncovered in March 2023 due to ACRO's investigation into a separate intrusion.
The ICO found that ACRO failed to apply patches and hotfixes released during the period they were running version 12.0.0 of Kentico CMS from September 2019 until March 2023, leaving known vulnerabilities unresolved. The watchdog also criticized poor communication between ACRO and its managed service provider, which did not learn about patching responsibilities until February 2020.
ACRO's lack of clear policies, responsibilities, and oversight arrangements for identifying and applying security updates contributed to the vulnerability. The organization's Trend Micro antivirus generated alerts but nobody appeared to be monitoring them. The records office told the ICO that it was unable to establish what business processes existed for assessing and handling security alerts at the time.
The breach exposed highly sensitive information including police certificate applications, subject access request forms, names, dates of birth, addresses, national insurance numbers, passport and driving license details, bank account information, biometric data, and criminal offense and special category information. ACRO notified 84,048 people of the breach but determined that only 10,920 individuals had potentially been targeted.
Despite the severity of the incident, ACRO was able to prevent the attackers from accessing other systems due to its network segmentation. However, the records office has made several improvements to its security since the attack was discovered, including decommissioning compromised infrastructure and implementing a security information and event management (SIEM) system.
The ICO's reprimand serves as a reminder of the importance of clear accountability for identifying and applying security updates and having effective monitoring in place. The organization's failure to prioritize cybersecurity highlights the need for better policies, responsibilities, and oversight arrangements. ACRO's response to the breach demonstrates an effort to strengthen its systems and safeguards, but it remains to be seen whether these changes will prevent similar incidents in the future.
The incident also raises concerns about the effectiveness of current cybersecurity measures and the importance of staying up-to-date with released patches and hotfixes. As organizations continue to process large volumes of highly sensitive personal information, it is essential that they prioritize their security and take proactive steps to protect against cyber threats.
In conclusion, the UK criminal records office data breach serves as a stark reminder of the critical vulnerabilities that can occur in even the most seemingly secure systems. The ICO's reprimand highlights the need for better policies, responsibilities, and oversight arrangements to prevent such incidents in the future. As cybersecurity measures continue to evolve, it is essential that organizations prioritize their security and take proactive steps to protect against cyber threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Exposing-Critical-Vulnerabilities-The-UK-Criminal-Records-Office-Data-Breach-ehn.shtml
https://www.theregister.com/security/2026/08/12/exposed-woeful-security-at-uk-criminal-records-office-that-led-to-sensitive-data-leak/5286736
Published: Wed Aug 12 09:59:45 2026 by llama3.2 3B Q4_K_M