Coming soon The Briev app is almost here. Leave your email and be first in on launch day.

Briev
Live
Technology

UK criminal records agency reprimanded after months-long breach exposed thousands of personal records

The UK’s ACRO criminal records office received an ICO reprimand after attackers accessed its website for over seven months, potentially compromising data on nearly 11,000 individuals.

The Information Commissioner’s Office reprimanded ACRO, the UK’s criminal records office, after uncovering a prolonged intrusion that began on 5 August 2022 and lasted until 14 March 2023. The breach stemmed from unpatched versions of the Kentico CMS, which the agency and its managed service provider failed to update despite available fixes. Alerts from Trend Micro antivirus went unreviewed, leaving the attackers able to stage a wide range of personal data—including names, birth dates, addresses, NI numbers and biometric details—for possible exfiltration in mid-February 2023.

Although ACRO notified 84,048 individuals, the ICO determined that data relating to no more than 10,920 people may have been exposed, leading to 35 complaints about identity-theft risk. Network segmentation prevented the attackers from moving beyond the CMS, and ACRO has since decommissioned the vulnerable infrastructure, introduced a SIEM, improved monitoring and migrated to Salesforce Experience Cloud. ICO investigator Jonathan Balmforth highlighted the case as a reminder that clear accountability and robust monitoring are as vital as technology in protecting sensitive information.

Why it matters

It shows how basic security lapses can endanger millions of personal records and underscores the need for rigorous patch management.

In this story

ACRO data breachICO reprimandKentico CMSpersonal data exposurepatch managementnetwork segmentationSIEMcybersecurity incidentdata protection