Ico.Uk
ACRO Cybersecurity Failings Expose Data of Nearly 11,000 Individuals
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The UK's ACRO Criminal Records Office faced a reprimand from the Information Commissioner's Office (ICO) after a hacker gained unauthorized access to its website and content management system (CMS) from August 2022 to March 2023. The breach potentially exposed sensitive personal information of up to 10,920 individuals, including names, dates of birth, and biometric data. Despite the prolonged access, ACRO could not confirm if any data was exfiltrated. The ICO's investigation revealed poor patch management and inadequate monitoring of security alerts as key failings. ACRO had not applied necessary patches to its Kentico CMS, leaving it vulnerable. The ICO opted for a reprimand rather than a fine, citing mitigating factors such as network segmentation that limited the attack's impact. ACRO has since decommissioned compromised systems and implemented improved security measures.
Key Points: • ACRO's website was compromised for over seven months, affecting up to 10,920 individuals. • Sensitive data potentially exposed includes personal identifiers and criminal records. • The ICO cited poor patch management and lack of monitoring as primary security failings.