ACRO Cybersecurity Failings Expose Data of Nearly 11,000 Individuals

ACRO Cybersecurity Failings Expose Data of Nearly 11,000 Individuals

First seen 12 Aug 2026, 14:07 UTC Ico.UkPoliceprofessionalTheregisterInfosecurity-MagazineWired-Gov+1 85% similarity 54.8

Article Content

Browse articles
ThreatCluster

The UK's ACRO Criminal Records Office faced a reprimand from the Information Commissioner's Office (ICO) after a hacker gained unauthorized access to its website and content management system (CMS) from August 2022 to March 2023. The breach potentially exposed sensitive personal information of up to 10,920 individuals, including names, dates of birth, and biometric data. Despite the prolonged access, ACRO could not confirm if any data was exfiltrated. The ICO's investigation revealed poor patch management and inadequate monitoring of security alerts as key failings. ACRO had not applied necessary patches to its Kentico CMS, leaving it vulnerable. The ICO opted for a reprimand rather than a fine, citing mitigating factors such as network segmentation that limited the attack's impact. ACRO has since decommissioned compromised systems and implemented improved security measures.

Key Points: • ACRO's website was compromised for over seven months, affecting up to 10,920 individuals. • Sensitive data potentially exposed includes personal identifiers and criminal records. • The ICO cited poor patch management and lack of monitoring as primary security failings.

ThreatCluster AI How this analysis works

Timeline

2022-08-05
Initial breach of ACRO's CMS
A hacker gained unauthorized access to ACRO's website and CMS, initiating a prolonged security incident.
The Register
2023-03-14
Breach discovered during separate investigation
The ICO uncovered the breach while investigating a different intrusion, revealing persistent access since August 2022.
The Register
2023-04-01
ACRO publicly disclosed the cybersecurity incident
ACRO announced the breach, stating it had no evidence of data compromise at that time.
The Register
2026-08-12
ICO issues reprimand to ACRO
The ICO formally reprimanded ACRO for security failings that led to the data exposure, highlighting inadequate patch management.
Wired-Gov
2026-08-13
ACRO implements remedial actions
Following the reprimand, ACRO decommissioned compromised infrastructure and improved security monitoring.
Infosecurity-Magazine

Community

Browse all →

Tracked Entities in This Story