UK Criminal Records Office Reprimanded After Three Undetected Intrusions Over Two Years
The UK Information Commissioner's Office (ICO) has censured ACRO Criminal Records Office โ the national policing unit handling sensitive data stored on the Police National Computer โ after hackers successfully compromised it in three separate intrusions between July 2021 and June 2023, exposing personal data of thousands of people including victims of domestic violence.
Key Facts
| Attribute | Detail |
|---|---|
| Regulator | UK ICO (reprimand notice) |
| Victim | ACRO Criminal Records Office (UK policing) |
| Intrusions | Three, July 2021 โ June 2023, all via the public-facing customer portal |
| Root causes | Kentico CMS unpatched since September 2019 with known, publicly documented vulnerabilities; no ownership of patching between ACRO, MSP and web developer |
| Alert failures | Trend Micro alerts unread โ including four quarantined detections of Mimikatz credential harvesting |
| Sensitivity | Records of domestic-violence victims among those exposed |
Context
The reprimand is a textbook case of foundational hygiene failures: unclear patch ownership across a three-party supply chain and ignored security alerts over a two-year intrusion window. It is directly transferable to AU and NZ public-sector agencies running internet-facing CMS platforms, and mirrors the kind of basic-hygiene failures OAIC's Notifiable Data Breaches scheme and the Privacy Act 2020 72-hour notification regime are designed to expose.
Related Pages
- Lazarus Exploits Windows Zero Day To Gain System Access And Deploy Backdoor โ same-week Windows zero-day exploitation
Sources: raw/digests/Cyber-Digest-2026-08-13