UK Criminal Records Office Breached 3 Times in 2 Years Over Unpatched CMS
Britain's ACRO Criminal Records Office has been formally reprimanded by the Information Commissioner's Office (ICO) after suffering three separate cyber intrusions between July 2021 and June 2023 that exposed the personal data of nearly 11,000 people, including victims of domestic violence. The national policing unit, which manages sensitive records stored on the Police National Computer, failed to apply critical security patches for nearly four years and ignored repeated warnings from its Trend Micro antivirus solution—including four separate detections of attempts to install the Mimikatz credential-harvesting tool. The ICO concluded that basic security lapses allowed attackers to maintain persistent access for months, staging sensitive data for exfiltration as early as February 2023.
All three incidents exploited ACRO's public-facing customer portal, which was built on the Kentico content management system and had been running the same version since September 2019 despite multiple known, publicly documented vulnerabilities. Although Kentico had shipped security patches for these flaws, none were applied because ACRO, its managed service provider, and its web development supplier were each unaware of who bore responsibility for monitoring and deploying updates. A parallel breakdown occurred in alert handling: ACRO told investigators it could not establish which business process governed security alerts or which roles were responsible for reviewing and escalating them. Anyone concerned about exposure in this or similar incidents can verify their status using our email breach checker.
The most serious incident, classified as "Group A," saw the attacker maintain persistent access to ACRO's website and CMS for approximately seven months between August 2022 and March 2023, conducting reconnaissance and ultimately staging the data of just under 11,000 individuals for exfiltration. Two additional incidents—codenamed Group B and Group C—were also uncovered during the forensic investigation, though it remains unclear whether they represent separate threat actors or successive stages of a single coordinated campaign. The compromised infrastructure was not decommissioned until June 22, 2023. Organizations running legacy CMS platforms should audit their patch management processes immediately and run a privacy checkup alongside an SSL/TLS checker to verify their public-facing assets are not exposing similar unpatched weaknesses.