Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-13 ยท updated: 2026-08-13 ยท tags: [incident, government, uk, ico, acro, cms, unpatched, regulatory-enforcement] ยท confidence: high ยท affected_sectors: [government, policing] ยท au_impact: true

UK Criminal Records Office Reprimanded After Three Undetected Intrusions Over Two Years

The UK Information Commissioner's Office (ICO) has censured ACRO Criminal Records Office โ€” the national policing unit handling sensitive data stored on the Police National Computer โ€” after hackers successfully compromised it in three separate intrusions between July 2021 and June 2023, exposing personal data of thousands of people including victims of domestic violence.

Key Facts

Attribute Detail
Regulator UK ICO (reprimand notice)
Victim ACRO Criminal Records Office (UK policing)
Intrusions Three, July 2021 โ€“ June 2023, all via the public-facing customer portal
Root causes Kentico CMS unpatched since September 2019 with known, publicly documented vulnerabilities; no ownership of patching between ACRO, MSP and web developer
Alert failures Trend Micro alerts unread โ€” including four quarantined detections of Mimikatz credential harvesting
Sensitivity Records of domestic-violence victims among those exposed

Context

The reprimand is a textbook case of foundational hygiene failures: unclear patch ownership across a three-party supply chain and ignored security alerts over a two-year intrusion window. It is directly transferable to AU and NZ public-sector agencies running internet-facing CMS platforms, and mirrors the kind of basic-hygiene failures OAIC's Notifiable Data Breaches scheme and the Privacy Act 2020 72-hour notification regime are designed to expose.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-13