ACRO Data Breach: Persistent Kentico CMS Attack Exposed Sensitive Records

ICO reprimands UK criminal records office after long‑running CMS breach

The ACRO data breach has highlighted significant cybersecurity weaknesses at the UK criminal records office. Attackers exploited unpatched Kentico CMS software, maintaining undetected access for over seven months and potentially exposing the sensitive data of up to 10,920 individuals.

Attack Timeline: Seven Months of Undetected Access

The incident at ACRO, the UK’s criminal records office, began on 5 August 2022, when attackers first gained persistent access to both the organisation’s public website and its underlying Kentico content management system. It was not until 14 March 2023 that the breach was uncovered, and only then as a byproduct of an investigation into a separate intrusion involving SQL injection and staff credential compromise.

According to the Information Commissioner’s Office (ICO), attackers used the window of opportunity created by a backlog of unaddressed security patches and unclear vendor responsibilities. ACRO had been running Kentico CMS version 12.0.0 since September 2019, but had failed to apply any patches or hotfixes released in the subsequent years. This left known vulnerabilities open for exploitation.

The ICO’s investigation revealed that the attackers maintained undetected access for over seven months, staging sensitive data for possible exfiltration during February 2023. Specifically, the staging occurred between 15 and 16 February, with the data readied for extraction in a manner that could not be conclusively tracked due to poor system logging.

Who Was Affected and What Data Was At Risk?

The ACRO data breach affected individuals who had submitted a variety of sensitive forms and applications, including:

  • Police Certificate Applications
  • Subject Access Request (SAR) forms
  • International Child Protection Certificate forms

The potentially exposed data included:

  • Full names, dates of birth and addresses
  • National Insurance numbers
  • Passport and driving licence details
  • Bank account information
  • Biometric data
  • Highly sensitive criminal offence and special category information

While ACRO originally notified 84,048 people about the breach, subsequent investigation determined that data relating to up to 10,920 individuals was actually staged for potential exfiltration. The ICO documented at least 35 formal complaints from individuals expressing distress and concern about the risk of identity theft and financial loss. Many of these complainants were linked to police certificate applications for purposes such as overseas travel or employment.

How the Attackers Exploited ACRO’s Weaknesses

The persistent nature of the breach was made possible by a combination of technical and organisational shortcomings:

  • Missed Patches: Kentico CMS version 12.0.0, installed in September 2019, was never updated with subsequent patches or hotfixes up to March 2023.
  • Unclear Vendor Responsibilities: ACRO’s managed service provider did not realise it was responsible for patching the CMS until February 2020, and even then did not actively monitor for new security updates.
  • Lack of Policy: No documented policy covered patch management for Kentico CMS, nor were there clear processes for identifying or prioritising vulnerabilities.
  • Ignored Security Alerts: ACRO’s Trend Micro antivirus system generated alerts, but there were no processes or identified roles responsible for reviewing or acting on these warnings. As a result, alerts went unread and unaddressed.
  • Poor Logging: The lack of robust logging made it impossible for investigators to determine whether data was actually exfiltrated, though evidence confirms it was prepared for removal.

The attackers were able to exploit these gaps to maintain uninterrupted access, move laterally within the system, and stage sensitive information for possible theft. The breach was only discovered by chance during the investigation of a separate SQL injection incident that compromised at least 15 sets of credentials, mostly belonging to ACRO staff.

Regulatory Response and Current Exploitation Status

The ICO issued a formal reprimand to ACRO rather than a financial penalty. The regulatory findings emphasised ACRO’s failure to patch known vulnerabilities, lack of operational monitoring, and poor governance over vendor responsibilities. The reprimand underscores the ICO’s expectations for public sector organisations to maintain robust patch management, clear vendor contracts, and effective security monitoring.

As of the conclusion of the investigation, there is no direct evidence that the staged data was exfiltrated or misused. However, the inability to definitively confirm or deny exfiltration is a direct result of ACRO’s inadequate logging practices. The incident remains a cautionary example of how persistent attackers can remain undetected in poorly maintained environments for extended periods.

Why This ACRO Data Breach Matters

This breach demonstrates how prolonged neglect of basic cybersecurity practices, such as patch management and logging, can expose highly sensitive government-held data. The fact that attackers could persist for months without detection, even as security alerts were generated, highlights the need for clearly defined roles, responsibilities, and monitoring processes in managing public sector IT systems.

Key Actions for Organisations

  • Review patch management processes and ensure clarity around third-party responsibilities.
  • Establish documented security procedures for monitoring alerts and responding to incidents.
  • Implement robust logging and regular audits to detect unusual access or data staging activities.

Although ACRO avoided a fine, this incident should serve as a wake-up call for any organisation handling sensitive personal data.

Originally reported by theregister.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call