UK Criminal Records Office Reprimanded After Nearly Two Years of Breaches Exposing Sensitive Data
The **Information Commissionerβs Office (ICO)** has issued a formal reprimand to the **ACRO Criminal Records Office** following a series of security failures that led to three separate breaches over nearly two years. These incidents exposed the personal data of thousands, including victims of domestic violence, highlighting critical deficiencies in patch management and alert handling.
Britain's national policing unit, the **ACRO Criminal Records Office**, has been censured by the countryβs data protection regulator, the **ICO**, for persistent security shortcomings that resulted in multiple data breaches between July 2021 and June 2023.
The reprimand notice details a litany of failures, including unheeded antivirus alerts and a critical system left unpatched for nearly four years.
### Systemic Vulnerabilities Exploited
All three attacks successfully compromised ACROβs public-facing customer portal, which was built on the **Kentico** content management system. This system had been running the same version since September 2019, despite containing multiple known and publicly documented vulnerabilities.
Crucially, **Kentico** had released security fixes for these issues, but ACRO failed to apply any of them. The investigation revealed a critical breakdown in responsibility, with neither ACRO, its managed service provider, nor its web development supplier knowing who was accountable for monitoring and applying patches.
### Ignored Security Alerts
Similar issues plagued ACRO's alert handling processes. The system's **Trend Micro** cybersecurity solution generated numerous warnings during the attack period, including quarantining four separate attempts to install the **Mimikatz** credential-harvesting tool. However, all these alerts went unheeded.
ACRO informed the ICO that it could not establish what business process existed for assessing or handling security alerts, nor which roles were responsible for reviewing and escalating them. The ICO concluded that timely action on these alerts could have prevented further malicious activity.
### The Nature of the Intrusions
While the perpetrators remain unidentified, a forensic investigation commissioned by ACRO uncovered three distinct incidents, labeled Group A, Group B, and Group C. It is unclear whether these represent separate threat actors or different stages of a single prolonged attack.
Evidence of attacker activity was observed between July 9, 2021, and June 22, 2023. The most severe incident, Group A, involved an attacker maintaining persistent access to ACROβs website and CMS for approximately seven months, from August 2022 to March 2023.
During this period, the attacker conducted reconnaissance and, in February 2023, staged the sensitive data of just under 11,000 individuals for exfiltration. A critical lack of sufficient logs meant ACRO could not definitively confirm whether the data was ultimately exfiltrated.
The other incidents, though not detailed extensively, included an SQL injection that exposed employee credentials.
### Disclosure and Aftermath
ACRO initially attributed its website downtime to essential maintenance. However, following inquiries from the Evening Standard newspaper, the office disclosed in April 2023 that it was responding to a cybersecurity incident.
The **Medusa** ransomware group subsequently claimed responsibility, though no stolen data was ever published on their leak site. This leaves open questions about a possible quiet extortion payment or a fabricated claim for publicity.
As a precautionary measure, ACRO notified over 84,000 individuals in April 2023 whose applications were submitted during the at-risk window. This resulted in more than 40 formal complaints, which the ICO did not investigate.
### Mitigating Factors and Future Steps
The ICO's reprimand places blame on ACRO as an institution, rather than specific individuals or management roles. A key mitigating factor cited by the regulator was that network segmentation prevented the attackers from moving beyond the compromised web environment into the core policing system, thus avoiding a financial penalty.
ACRO has since decommissioned the compromised infrastructure and implemented a new security information and event management system. The office did not respond to requests for comment.