Published Security3 min read
ACRO's reprimand is a list of the failures the ICO will now name out loud
A criminal records office ran an internet-facing CMS on a 2019 build, could not say who owned patching, and could not name anyone responsible for reading antivirus alerts. Three intrusions followed over two years.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- The ICO reprimanded ACRO Criminal Records Office after it was repeatedly breached over nearly two years, exposing the personal data of thousands of people including victims of domestic violence.
- The ICO announced the reprimand notice on Wednesday, censuring ACRO over a range of security shortcomings including alerts from antivirus software going unread and a critical system left unpatched for nearly four years.
- ACRO is the national policing unit that handles a range of sensitive data stored on the Police National Computer.
- Failures at ACRO allowed hackers to compromise the office in three separate intrusions between July 2021 and June 2023.
- All three attacks exploited ACRO's public-facing customer portal, built on the Kentico content management system, which had been running the same version since September 2019 despite containing multiple known and publicly documented vulnerabilities.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Britain's Information Commissioner's Office has reprimanded ACRO Criminal Records Office after attackers compromised its public-facing customer portal in three separate intrusions between July 2021 and June 2023 [4], with the regulator citing antivirus alerts that went unread and a critical system left unpatched for nearly four years [2]. ACRO is the national policing unit that handles sensitive data stored on the Police National Computer [3], and the data exposed included that of victims of domestic violence [1].
The anchor fact is unglamorous. All three attacks hit the same customer portal, built on the Kentico content management system, which had been running the same version since September 2019 despite containing multiple known and publicly documented vulnerabilities [5]. That is roughly 45 months of a static build on an internet-facing asset [1]. Kentico had shipped security fixes for those issues; ACRO applied none of them, because neither ACRO, nor its managed service provider, nor its web development supplier knew who was meant to be watching for and applying patches [6]. The suppliers are redacted throughout the notice [21].
Detection was not the problem. The Trend Micro product on the system issued numerous warnings during the attack period, including quarantining four separate detections of attempts to install the Mimikatz credential-harvesting tool, and all of them went unheeded [7]. Asked to explain, ACRO told the ICO it could not establish what business process had existed for assessing or handling security alerts, and did not know which roles had been responsible for reviewing and escalating them [8]. The ICO concluded that acting on those alerts could have prevented further malicious activity [9].
A forensic investigation commissioned by ACRO identified three distinct incidents, labelled Group A, Group B and Group C, and it is not clear whether those labels represent separate perpetrators or stages of one campaign [11]. Who was responsible remains unknown [10]. Group A, described as the most serious, held persistent access to the website and CMS for about seven months, from August 2022 to March 2023 [13]. In February 2023, roughly six months into that access [2], the attacker staged the sensitive data of just under 11,000 people for exfiltration [14]. ACRO had not retained enough logs to confirm whether the data actually left [15]. One of the other incidents involved an SQL injection that exposed employee credentials [16]. Evidence of attacker activity runs from July 9, 2021 to June 22, 2023, though the ICO notes the closing date is when the compromised infrastructure was decommissioned, not when the attacker was last inside [12].
The public handling followed the familiar order. ACRO first said the website was down for essential maintenance, then disclosed in April 2023, after contact from the Evening Standard, that it had been responding to a cybersecurity incident [17]. The Medusa ransomware group claimed responsibility but never published anything on its leak site, leaving open whether a payment was made quietly or the claim was invented [18]. ACRO notified more than 84,000 applicants as a precaution [19] - the staged 11,000 amount to about 13 percent of that population [3] - and more than 40 formal complaints followed, which the ICO said it did not investigate [20].
Two things are worth tracking. The ICO assigns fault to ACRO as an institution and names no individual or management role [21], which sets the expectation that patch ownership, alert triage roles and log retention are corporate controls rather than someone's initiative. And the sanction here is a reprimand [1], so the deterrent value depends entirely on other controllers reading the notice as a checklist against their own supplier contracts. Network segmentation is credited with limiting the attacker's movement [22]; it was the only control that worked.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The ICO reprimanded ACRO Criminal Records Office after it was repeatedly breached over nearly two years, exposing the personal data of thousands of people including victims of domestic violence.
- [2]
The ICO announced the reprimand notice on Wednesday, censuring ACRO over a range of security shortcomings including alerts from antivirus software going unread and a critical system left unpatched for nearly four years.
- [3]
ACRO is the national policing unit that handles a range of sensitive data stored on the Police National Computer.
ReportedView cited source - [4]
Failures at ACRO allowed hackers to compromise the office in three separate intrusions between July 2021 and June 2023.
ReportedView cited source - [5]
All three attacks exploited ACRO's public-facing customer portal, built on the Kentico content management system, which had been running the same version since September 2019 despite containing multiple known and publicly documented vulnerabilities.
ReportedView cited source - [6]
Kentico had shipped security fixes for the vulnerabilities, but ACRO applied none of them because neither ACRO, nor the managed service provider, nor the web development supplier knew who was meant to be watching for and applying the patches.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- therecord.mediaAug 12Three intrusions at UK criminal records office went undetected for two years
Cited in this coverage: therecord.media
Cited in this coverage: ICO reprimand notice, via therecord.media
Additional citations
- ICO



