← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

UK Criminal Records Office Breached for Two Years Due to Unpatched Systems and Unread Alerts

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • ACRO Criminal Records Office breached three times between July 2021 and June 2023.
  • Intrusions exploited unpatched Kentico CMS with known vulnerabilities.
  • Antivirus alerts, including Mimikatz detections, went unheeded.
  • ICO reprimanded ACRO for security shortcomings and data exposure.

Data Breaches at ACRO Criminal Records Office

The ACRO Criminal Records Office, a national policing unit in the UK, was reprimanded by the Information Commissioner’s Office (ICO) following three separate security intrusions. These breaches, occurring between July 2021 and June 2023, led to the exposure of personal data belonging to thousands of individuals, including victims of domestic violence.

Systemic Security Failures Identified

The ICO's reprimand detailed a range of security shortcomings at ACRO. A critical system remained unpatched for nearly four years, and alerts from antivirus software were not reviewed. The intrusions specifically exploited ACRO’s public-facing customer portal, which was built on the Kentico content management system. This system had been running an outdated version since September 2019, despite containing multiple known and publicly documented vulnerabilities for which Kentico had released security fixes.

Ignored Security Alerts

During the attack period, the system's Trend Micro cybersecurity solution generated numerous warnings, including quarantining four attempts to install the Mimikatz credential-harvesting tool. However, ACRO failed to act on these alerts. The office informed the ICO that it lacked a clear business process for assessing or handling security alerts and did not know which roles were responsible for reviewing and escalating them. The ICO concluded that timely action on these alerts could have prevented further malicious activity.

Unidentified Perpetrators

The identity of the perpetrators behind the three incidents remains unclear, as does whether they were separate threat actors or stages of a single attack. A forensic investigation commissioned by ACRO identified three distinct incidents, labeled Group A, Group B, and Group C, but did not clarify if these groupings referred to different actors or activity clusters. Attacker activity was observed from July 9, 2021, to June 22, 2023.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The UK's ACRO Criminal Records Office received a reprimand from the Information Commissioner’s Office (ICO) after three intrusions over nearly two years exposed personal data, including that of domestic violence victims. The breaches occurred due to unpatched systems and ignored security alerts, highlighting significant security failures within the organization.