UK Criminal Records Office Breach Exposes 10,920 Individuals
The UK's criminal records office (ACRO) disclosed a cybersecurity incident in April 2023 involving potential exposure of sensitive data for 10,920 individuals. Attackers maintained persistent access to ACRO's website and Kentico content management system from August 5, 2022, to March 14, 2023. ACRO used Kentico CMS version 12.0.0 without applying security patches from September 2019 to March 2023. The Information Commissioner's Office (ICO) reprimanded ACRO in March 2023 instead of imposing a financial penalty due to public sector status. ACRO notified 84,048 people of the breach, but investigators determined only 10,920 individuals had data staged for potential exfiltration. The ICO confirmed ACRO's network segmentation prevented attackers from accessing systems beyond the compromised CMS. ACRO received 35 formal complaints citing personal distress and identity theft risks from affected individuals.
The breach occurred due to ACRO's failure to apply security patches to Kentico CMS for 3 years, coupled with a lack of documented policies for identifying, prioritizing, or applying patches. Trend Micro antivirus generated security alerts that were not reviewed by personnel during the incident, and ACRO's managed service provider did not assume responsibility for security patching until February 2020.
This incident erodes trust in digital systems critical for vulnerable populations, enabling identity theft and fraud. For individuals relying on secure access to criminal records for housing, employment, or legal services, the risk of compromised personal data—such as national insurance numbers, biometric data, and criminal records—creates significant friction in accessing basic security and stability.
The ICO confirmed ACRO could not determine whether actual data exfiltration occurred due to poor logging and undocumented security processes. With 6 additional complaints reported to the ICO, the incident highlights systemic gaps in public sector cybersecurity that could worsen for vulnerable populations if unaddressed. The source provides detailed evidence of the breach's scope and causes but cannot confirm actual data theft or full remediation timelines.
Source: The Register
MANY MINDED