2 Remove Virus

UK criminal records office reprimanded over breach affecting sensitive personal data

The UK’s Information Commissioner’s Office (ICO) has reprimanded the ACRO Criminal Records Office following an investigation into cybersecurity weaknesses that left highly sensitive personal information potentially accessible to an attacker. More than 10,000 people were directly affected by the security incident, while ACRO ultimately contacted 84,048 individuals who could potentially have been impacted.

 

 

The unauthorized activity occurred between August 2022 and March 2023 and involved ACRO’s public website and its Kentico content management system. According to the ICO, the attacker gained access to an environment containing extensive personal information processed by the organization as part of its criminal records services.

The potentially exposed records were particularly sensitive. They included names, dates of birth, addresses, National Insurance numbers, passport and driving licence information, banking details and biometric information. The affected environment also contained criminal-offence records and special-category data involving areas such as disability, race or ethnic origin, sexual orientation and gender reassignment.

Despite the attacker’s access, investigators have not established that the information was actually removed from ACRO’s systems. The ICO therefore distinguishes between data that was potentially accessible during the compromise and information confirmed as exfiltrated. ACRO nevertheless decided in April 2023 to notify 84,048 people because of the potential risk.

The consequences of that uncertainty were significant for some recipients. ACRO received 35 complaints following its notifications, including complaints from people who had experienced domestic violence and were concerned about the possibility that their personal information had been exposed.

The ICO’s investigation concentrated on two major security problems: inadequate patch management and insufficient monitoring of security warnings. ACRO relied on a managed service provider to maintain parts of its technology environment, including operating-system updates and monthly maintenance. However, responsibility for updating the Kentico CMS was not covered by that arrangement.

ACRO itself was not monitoring the CMS to determine whether security patches needed to be installed. The regulator found that the software contained multiple known vulnerabilities during the period relevant to the attack, leaving a significant gap in ACRO’s security oversight.

The second problem involved security alerts that were generated but not properly handled. ACRO had deployed Trend Micro security software capable of identifying suspicious activity and malware. The system produced alerts, but the ICO found that those warnings were neither adequately reviewed nor acted upon.

According to the regulator, investigating those alerts when they appeared could likely have allowed ACRO to respond earlier and prevent additional malicious activity. The failure was therefore not simply the absence of security technology; protective software was already present, but the organization lacked an effective process for responding to what it detected.

One security measure did work as intended. ACRO had segmented the affected environment from its core policing infrastructure. The ICO found that this separation prevented the attacker from moving from the compromised systems into more sensitive operational policing networks, limiting the potential consequences of the intrusion.

The regulator’s reprimand requires ACRO to address the organizational weaknesses identified during the investigation. The ICO emphasized the importance of clearly assigning responsibility for finding, assessing and installing security updates, while ensuring that security warnings are actively investigated rather than simply collected.

The case ultimately demonstrates that ACRO’s breach was not attributed solely to sophisticated attacker capabilities. The ICO’s findings instead identified shortcomings in fundamental security processes, particularly the management of known software vulnerabilities and the response to alerts generated by existing defensive systems.