The UK's criminal records office maintained undetected security vulnerabilities that allowed attackers persistent access to sensitive systems for more than seven months, potentially exposing data belonging to nearly 11,000 people. The Information Commissioner's Office issued a formal reprimand to ACRO rather than imposing a financial penalty, revealing that the breach was only discovered in March 2023 while investigators examined a separate intrusion. ACRO initially disclosed the incident in April 2023, saying at the time it had no evidence any data was compromised, but regulators have now confirmed attackers staged sensitive information for possible theft.
The intrusion began on August 5, 2022, and continued undetected until March 14, 2023, according to the ICO's findings. ACRO ran version 12.0.0 of its Kentico content management system from September 2019 through March 2023 without applying patches and hotfixes released during that period, leaving known security holes unaddressed. Potentially exposed material included police certificate applications, subject access request forms, international child protection certificate forms, names, dates of birth, addresses, national insurance numbers, passport and driving license details, bank account information, biometric data, and highly sensitive criminal offense information. ACRO notified 84,048 people of the breach, though investigators later determined that data relating to no more than 10,920 individuals had potentially been staged for removal from the network. The office received 35 formal complaints citing personal distress and worry about identity theft and financial loss, with complainants including those connected to police certificates, international child protection certificates, and victims of domestic violence. The ICO received an additional six complaints raising similar concerns.
The breach stemmed from poor communication between ACRO and its managed service provider, the regulator found. The supplier didn't learn that patching was its responsibility until February 2020 and continued to assume it wasn't required to actively monitor for security updates. ACRO lacked a documented policy covering Kentico CMS patching and couldn't show how vulnerabilities were identified or prioritized. The office's Trend Micro antivirus generated alerts, but the organization told the ICO it was "unable to establish what business processes existed for the assessment or handling of security alerts at the relevant time" and couldn't identify which roles were responsible for reviewing these warnings, ultimately causing them to go unread. Poor logging meant that despite an extensive investigation by a third-party cybersecurity firm, it remains impossible to determine whether the affected data was actually stolen.
Jonathan Balmforth, group manager of civil and cyber investigations at the ICO, said organizations must ensure there's clear accountability for identifying, assessing, and applying security updates, and must have effective monitoring so that warning signs of cyberattacks are identified, investigated, and acted upon promptly. ACRO's network segmentation prevented attackers from moving beyond the CMS into other systems, according to the ICO, which served as the organization's saving grace. Since the attack was discovered, ACRO has decommissioned the compromised infrastructure, implemented a security information and event management system, improved visibility and monitoring, hardened systems, and migrated to Salesforce Experience Cloud. The regulator chose to issue a reprimand rather than a monetary penalty, a tool often used for public sector organizations to avoid draining public funds. The case shows how basic cybersecurity failures can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information, and the lessons are clear: having the right policies, responsibilities, and oversight arrangements is just as important as having the right technology. Public sector organizations face a fundamental tension between accountability and budgets, and this incident illustrates why regulators must reconsider whether administrative warnings adequately deter negligence when the consequences fall on vulnerable citizens rather than shareholders.

