The ACRO Criminal Records Office, a national policing unit in the UK, was reprimanded by the Information Commissioner’s Office (ICO) following three separate security intrusions. These breaches, occurring between July 2021 and June 2023, led to the exposure of personal data belonging to thousands of individuals, including victims of domestic violence.
The ICO's reprimand detailed a range of security shortcomings at ACRO. A critical system remained unpatched for nearly four years, and alerts from antivirus software were not reviewed. The intrusions specifically exploited ACRO’s public-facing customer portal, which was built on the Kentico content management system. This system had been running an outdated version since September 2019, despite containing multiple known and publicly documented vulnerabilities for which Kentico had released security fixes.
During the attack period, the system's Trend Micro cybersecurity solution generated numerous warnings, including quarantining four attempts to install the Mimikatz credential-harvesting tool. However, ACRO failed to act on these alerts. The office informed the ICO that it lacked a clear business process for assessing or handling security alerts and did not know which roles were responsible for reviewing and escalating them. The ICO concluded that timely action on these alerts could have prevented further malicious activity.
The identity of the perpetrators behind the three incidents remains unclear, as does whether they were separate threat actors or stages of a single attack. A forensic investigation commissioned by ACRO identified three distinct incidents, labeled Group A, Group B, and Group C, but did not clarify if these groupings referred to different actors or activity clusters. Attacker activity was observed from July 9, 2021, to June 22, 2023.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The UK's ACRO Criminal Records Office received a reprimand from the Information Commissioner’s Office (ICO) after three intrusions over nearly two years exposed personal data, including that of domestic violence victims. The breaches occurred due to unpatched systems and ignored security alerts, highlighting significant security failures within the organization.