Skip to main content
Emerging ThreatsData Breaches

UK Watchdog Reprimands ACRO for 2023 Data Breach Failings

Government agency office interior with blurred computer screen and UK flag in background.

10,920 people were recorded as potentially affected after a hacker had unauthorized access to the Criminal Records Office’s (ACRO) website and content management system between August 2022 and March 2023, the Information Commissioner’s Office (ICO) says.

How the intrusion unfolded against ACRO’s Kentico CMS

The ICO found the breach stemmed from persistent access to ACRO’s website and its Kentico content management system (CMS) over an eight-month window. Responsibilities for applying security patches were split across suppliers: ACRO’s managed service provider (MSP) handled operating-system patches but not the Kentico CMS; the policing agency’s web development supplier was “responsible for applying patches to the CMS, but not identifying when patches were required,” the ICO said. The watchdog concluded that “ACRO itself did not monitor for required security patches, meaning that there was an absence of oversight for this important security control.”

Unreviewed Trend Micro alerts and weak monitoring

ACRO had a Trend Micro solution installed to “detect and quarantine malware,” but the ICO reported that the alerts it generated “were not reviewed or acted upon.” The ICO warned that “Had the alerts been investigated by ACRO at the time, and an appropriate response conducted, it is likely that further malicious activity could have been prevented.” The ruling therefore emphasises not only patch hygiene but active alert triage and investigation as essential controls.

What the breach exposed and who complained

Although poor record keeping at ACRO means it remains unclear whether attackers actually exfiltrated the information tied to the 10,920 victims, the ICO’s findings list the types of data that were exposed. The breach potentially revealed names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and “highly sensitive criminal offence and special category information.” Dozens of complaints were made to ACRO after the incident; several came from people connected to International Child Protection Certificates and from victims of domestic violence.

ICO reprimand, remedial actions and limited financial penalty

The ICO issued a formal reprimand to ACRO for breaching the UK’s data protection requirements. The regulator framed the GDPR infringement around two principal failings: poor patch management and insufficient security monitoring. In mitigation, the ICO noted that ACRO had network segmentation that reduced the blast radius of the attack and that the organisation undertook a series of remedial measures. These steps included “decommissioning the compromised infrastructure, migrating services elsewhere, implementing security monitoring, improving visibility of cyber threats and strengthening network segmentation.”

The ICO also indicated it was “likely” ACRO avoided a fine because of the regulator’s public sector approach, which limits financial penalties levied on that sector. Jonathan Balmforth, ICO group manager for civil and cyber investigations, summarised the regulator’s takeaway: “Organizations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyber-attacks are identified, investigated and acted upon promptly.” He added: “The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology.”

What this means for technologists, policymakers, and affected individuals

  • Technologists and security teams: The ICO’s findings underscore the need to define ownership for patching across all components — including third‑party CMS platforms — and to ensure alerting tools are actively reviewed and escalated. The regulator’s advice calls for “effective patch and vulnerability management and regular security testing.”
  • Policymakers and regulators: The decision highlights a tension in enforcement approaches: the ICO’s public sector policy can limit fines, even where significant personal data are involved, while still using reprimands and published findings to press for change.
  • Affected individuals and specialist complainants: For the 10,920 people recorded as impacted, the ICO’s note that record keeping was insufficient leaves open whether data were exfiltrated — a continuing source of uncertainty, particularly for those connected to International Child Protection Certificates and victims of domestic violence.

The ICO’s reprimand is a reminder that attacks frequently exploit organisational gaps as much as software flaws: when responsibility for updates is fragmented and alerts go unanalyzed, detection and response break down. In this case, ACRO’s subsequent decommissioning of compromised infrastructure and the introduction of monitoring acknowledge that technical fixes alone won’t replace clear accountability and operational oversight.

Source: Infosecurity Magazine — ICO Reprimands Criminal Records Office After 2023 Breach