BusinessCybersecurityNewswireTechnology

ICO Slaps Criminal Records Office Over 2023 Breach

Originally published on: August 14, 2026
▼ Summary

– The UK Information Commissioner’s Office (ICO) issued a reprimand to the Criminal Records Office (ACRO) for a 2023 data breach affecting over 10,000 people, caused by a hacker gaining unauthorized access to its website and content management system between August 2022 and March 2023.
– Due to ACRO’s poor record keeping, it is unclear whether the hacker actually exfiltrated the data of 10,920 victims, which included sensitive information like names, addresses, National Insurance numbers, bank details, biometric data, and criminal offense records.
– The GDPR breach was attributed to two security failings: poor patch management, where ACRO failed to oversee security patches for its Kentico CMS, and insufficient security monitoring, as alerts from its Trend Micro malware solution were not reviewed or acted upon.
– The ICO issued a reprimand rather than a fine, considering ACRO’s network segmentation that reduced the attack’s impact and its remedial actions, including decommissioning compromised infrastructure and implementing security monitoring; the agency likely avoided a fine due to the ICO’s public sector approach.
– The ICO advised organizations to ensure clear accountability for applying security updates and to have effective monitoring to promptly identify and act on cyber-attack warning signs, emphasizing that policies and oversight are as crucial as technology.

The UK’s information watchdog has formally censured the Criminal Records Office (ACRO) following a string of security shortcomings that culminated in a 2023 data breach affecting more than 10,000 individuals. The Information Commissioner’s Office (ICO) confirmed that between August 2022 and March 2023, an unauthorized actor gained entry to ACRO’s website and its content management system (CMS). Yet, due to ACRO’s own deficient record-keeping, the regulator stated it remains uncertain whether the intruder actually extracted the personal data tied to 10,920 victims.

The compromised information was extensive and highly sensitive, encompassing names, birth dates, addresses, National Insurance numbers, passport and driving licence particulars, bank account details, biometric records, and what the ICO described as “highly sensitive criminal offence and special category information.” Following the incident, ACRO received dozens of complaints, including from individuals associated with International Child Protection Certificates and from victims of domestic violence.

The ICO’s determination of a GDPR infringement rests on two central failures: inadequate patch management and a lack of robust security monitoring. According to the regulator, ACRO’s managed service provider (MSP) handled operating system patches but not those for the Kentico CMS platform. Meanwhile, the web development supplier applied CMS patches but was not tasked with flagging when those patches were necessary. The ICO noted that ACRO itself failed to track required security updates, leaving a critical gap in oversight for this essential control.

A second layer of negligence involved the agency’s malware defenses. Although ACRO had installed a Trend Micro solution designed to detect and quarantine malware, the alerts it produced were neither reviewed nor acted upon. The ICO’s report stated that if those alerts had been investigated promptly and responded to appropriately, it is likely that further malicious activity could have been prevented.

In deciding to issue a reprimand rather than a heavier penalty, the ICO acknowledged that ACRO had implemented network segmentation, which helped limit the attack’s blast radius, and that it took corrective steps afterward. Those actions included decommissioning the compromised infrastructure, migrating services to alternative systems, introducing security monitoring, enhancing visibility of cyber threats, and strengthening network segmentation. The agency likely avoided a financial fine because of the ICO’s public sector policy, which restricts monetary penalties for government bodies.

Jonathan Balmforth, the ICO’s group manager for civil and cyber investigations, offered a clear warning to other organizations. He stressed that businesses must ensure explicit accountability for identifying, assessing, and applying security updates, and that effective monitoring is essential so warning signs of cyber-attacks are spotted, investigated, and addressed without delay. He added that the lessons here are straightforward: having the right policies, responsibilities, and oversight structures is just as critical as deploying the right technology. The regulator’s guidance for other entities is to prioritize these governance fundamentals to avoid similar breaches.

(Source: Infosecurity Magazine)

Topics

data breach 100% gdpr violations 96% security failings 93% regulatory reprimand 90% patch management 87% security monitoring 84% sensitive data exposure 80% cyber attack 76% ico enforcement 72% public sector penalties 68%