The ACRO data breach has highlighted significant cybersecurity weaknesses at the UK criminal records office. Attackers exploited unpatched Kentico CMS software, maintaining undetected access for over seven months and potentially exposing the sensitive data of up to 10,920 individuals.
Attack Timeline: Seven Months of Undetected Access
The incident at ACRO, the UK’s criminal records office, began on 5 August 2022, when attackers first gained persistent access to both the organisation’s public website and its underlying Kentico content management system. It was not until 14 March 2023 that the breach was uncovered, and only then as a byproduct of an investigation into a separate intrusion involving SQL injection and staff credential compromise.
According to the Information Commissioner’s Office (ICO), attackers used the window of opportunity created by a backlog of unaddressed security patches and unclear vendor responsibilities. ACRO had been running Kentico CMS version 12.0.0 since September 2019, but had failed to apply any patches or hotfixes released in the subsequent years. This left known vulnerabilities open for exploitation.
The ICO’s investigation revealed that the attackers maintained undetected access for over seven months, staging sensitive data for possible exfiltration during February 2023. Specifically, the staging occurred between 15 and 16 February, with the data readied for extraction in a manner that could not be conclusively tracked due to poor system logging.
Who Was Affected and What Data Was At Risk?
The ACRO data breach affected individuals who had submitted a variety of sensitive forms and applications, including:
- Police Certificate Applications
- Subject Access Request (SAR) forms
- International Child Protection Certificate forms
The potentially exposed data included:
- Full names, dates of birth and addresses
- National Insurance numbers
- Passport and driving licence details
- Bank account information
- Biometric data
- Highly sensitive criminal offence and special category information
While ACRO originally notified 84,048 people about the breach, subsequent investigation determined that data relating to up to 10,920 individuals was actually staged for potential exfiltration. The ICO documented at least 35 formal complaints from individuals expressing distress and concern about the risk of identity theft and financial loss. Many of these complainants were linked to police certificate applications for purposes such as overseas travel or employment.
How the Attackers Exploited ACRO’s Weaknesses
The persistent nature of the breach was made possible by a combination of technical and organisational shortcomings:
- Missed Patches: Kentico CMS version 12.0.0, installed in September 2019, was never updated with subsequent patches or hotfixes up to March 2023.
- Unclear Vendor Responsibilities: ACRO’s managed service provider did not realise it was responsible for patching the CMS until February 2020, and even then did not actively monitor for new security updates.
- Lack of Policy: No documented policy covered patch management for Kentico CMS, nor were there clear processes for identifying or prioritising vulnerabilities.
- Ignored Security Alerts: ACRO’s Trend Micro antivirus system generated alerts, but there were no processes or identified roles responsible for reviewing or acting on these warnings. As a result, alerts went unread and unaddressed.
- Poor Logging: The lack of robust logging made it impossible for investigators to determine whether data was actually exfiltrated, though evidence confirms it was prepared for removal.
The attackers were able to exploit these gaps to maintain uninterrupted access, move laterally within the system, and stage sensitive information for possible theft. The breach was only discovered by chance during the investigation of a separate SQL injection incident that compromised at least 15 sets of credentials, mostly belonging to ACRO staff.
Regulatory Response and Current Exploitation Status
The ICO issued a formal reprimand to ACRO rather than a financial penalty. The regulatory findings emphasised ACRO’s failure to patch known vulnerabilities, lack of operational monitoring, and poor governance over vendor responsibilities. The reprimand underscores the ICO’s expectations for public sector organisations to maintain robust patch management, clear vendor contracts, and effective security monitoring.
As of the conclusion of the investigation, there is no direct evidence that the staged data was exfiltrated or misused. However, the inability to definitively confirm or deny exfiltration is a direct result of ACRO’s inadequate logging practices. The incident remains a cautionary example of how persistent attackers can remain undetected in poorly maintained environments for extended periods.
Why This ACRO Data Breach Matters
This breach demonstrates how prolonged neglect of basic cybersecurity practices, such as patch management and logging, can expose highly sensitive government-held data. The fact that attackers could persist for months without detection, even as security alerts were generated, highlights the need for clearly defined roles, responsibilities, and monitoring processes in managing public sector IT systems.
Key Actions for Organisations
- Review patch management processes and ensure clarity around third-party responsibilities.
- Establish documented security procedures for monitoring alerts and responding to incidents.
- Implement robust logging and regular audits to detect unusual access or data staging activities.
Although ACRO avoided a fine, this incident should serve as a wake-up call for any organisation handling sensitive personal data.
Originally reported by theregister.com.







