Skip to main content
Emerging ThreatsData Breaches

UK Criminal Records Office Breach Exposes 11,000 People's Sensitive Data

Government office interior with computer and filing cabinets in background.
"This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information," said Jonathan Balmforth, group manager of civil and cyber investigations at the Information Commissioner's Office (ICO).

How attackers gained and kept access

The ICO's reprimand makes plain that the most serious intrusion began on August 5, 2022, when attackers breached ACRO's website and its Kentico content management system. That access was persistent: the intruders remained undetected until March 14, 2023. The compromise was discovered only because ACRO was already investigating a separate SQL injection attack that had compromised 15 sets of credentials; that investigation in March 2023 exposed evidence of additional intrusions dating back to July 8, 2021.

Known technical failures: unpatched Kentico, missed alerts, and unclear responsibilities

ACRO ran Kentico CMS version 12.0.0 from September 2019 until March 2023 without applying the patches and hotfixes released during that period, leaving the platform vulnerable to known flaws. The ICO blamed "ambiguity around who was accountable for identifying necessary Kentico CMS patches" and found poor communication with ACRO's managed service provider. The supplier did not learn that patching was its responsibility until February 2020 and continued to assume it did not need to monitor actively for security updates.

Adding to the risk, ACRO's Trend Micro antivirus generated alerts that were not acted upon. For reasons redacted from the postmortem, ACRO told the ICO it was "unable to establish what business processes existed for the assessment or handling of security alerts at the relevant time" and could not identify which roles were responsible for reviewing those alerts. Weak logging prevented investigators from establishing whether data had been exfiltrated.

What was staged and who was told

Investigators determined that attackers staged potentially sensitive material for possible exfiltration between February 15 and 16, 2023. The categories of potentially exposed data included Police Certificate Applications, Subject Access Request (SAR) forms, International Child Protection Certificate forms, names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and "highly sensitive criminal offence and special category information."

ACRO initially notified 84,048 people of the cybersecurity incident. Subsequent analysis narrowed the scope of the most serious staging activity to data relating to no more than 10,920 individuals. Of those, ACRO received 35 formal complaints citing personal distress and concern about identity theft and financial loss; complainants included people connected to Police Certificates, International Child Protection Certificates, and victims of domestic violence. The ICO itself received six complaints.

Remediation taken and the ICO response

The ICO reprimanded ACRO rather than imposing a financial penalty, and it set out specific criticisms and lessons. The records office decommissioned the compromised website infrastructure (though not until June 2023), implemented a security information and event management (SIEM) system, improved visibility and monitoring, hardened systems, improved network segmentation, and migrated its services to Salesforce Experience Cloud. ACRO told The Register it "accept[s] the ICO's findings of the infringements" and highlighted that it "immediately took the previous website offline and subsequently decommissioned it" and "took steps to protect customers, including making sure anyone potentially affected was informed at the earliest possible stage."

What this means for technologists, regulators, and affected individuals

  • Technologists and security teams: The record underlines the operational consequences when patch responsibility is ambiguous, alerts are unread, and logging is insufficient. Teams will need to ensure documented patching policies, clear vendor responsibilities, and active alert-handling processes—exactly the gaps the ICO identified.
  • Policymakers and regulators: The ICO's decision to issue a reprimand rather than a fine signals emphasis on corrective action and public accountability; regulators will likely point to the case as an example of why demonstrable governance and oversight matter as much as technology.
  • Affected individuals (Police Certificate applicants, victims of domestic violence): Thousands were notified and tens of thousands were alerted; for more than 10,900 people the ICO found data had been staged for possible exfiltration. The publicly recorded complaints show concrete distress and concern about identity theft and financial loss.

Two elements remain particularly stark in the ICO's account: persistent, long-running access to a public-facing CMS coupled with failed human processes to act on security tools; and incomplete logs that leave open whether data actually left ACRO systems. The watchdog praised the remediation steps ACRO has taken and urged other organizations to learn from this case. The clear practical question left by the record is whether those remedial measures — documented patching responsibilities, effective alert triage, and improved logging — will be sustained and independently verified so that similar exposures cannot recur.

Source: The Register — Exposed: Woeful security at UK criminal records office that led to sensitive data leak