VYPR
breachPublished Aug 12, 2026· 2 sources

UK Criminal Records Office Suffered Three Undetected Data Breaches Over Two Years

Britain's ACRO criminal records office experienced three data breaches over two years due to unread antivirus alerts and an unpatched content management system, exposing sensitive data.

Britain's national criminal records office, ACRO, was the victim of three separate data breaches that went undetected for approximately two years. The security failures, detailed in a reprimand notice, stemmed from a combination of unread antivirus alerts and a critical vulnerability in an unpatched content management system, allowing attackers to access sensitive information.

The extent of the data compromised and the specific methods used by the attackers are still under investigation. However, the breaches highlight significant deficiencies in ACRO's cybersecurity posture, raising concerns about the protection of sensitive personal and criminal records.

According to the report, security teams failed to act on critical alerts generated by the office's antivirus software. This inaction meant that potential intrusions and malicious activities were not addressed in a timely manner, creating a window of opportunity for threat actors.

Compounding these issues, a content management system (CMS) used by ACRO remained unpatched for an extended period. This allowed attackers to exploit known vulnerabilities within the CMS to gain unauthorized access to the network and data.

The dual failures—ignoring critical alerts and leaving systems unpatched—created a perfect storm for attackers, enabling them to operate within the ACRO network for an extended duration without detection.

The reprimand notice suggests that the agency's internal security processes and incident response capabilities were inadequate, leading to the prolonged undetected presence of attackers.

This incident underscores the critical importance of timely patch management and diligent monitoring of security alerts. For government agencies handling sensitive data, such oversights can have severe consequences, including data compromise and erosion of public trust.

Further investigations are expected to reveal more details about the nature of the accessed data and the specific vulnerabilities exploited, potentially leading to recommendations for improved security practices within ACRO and similar public sector organizations.

This updated report from The Register provides further details on the ACRO data breach, specifically highlighting the Information Commissioner's Office (ICO) reprimand and the reasons behind it. It elaborates on the prolonged seven-month period of attacker access due to unpatched Kentico CMS vulnerabilities, the communication breakdown with the managed service provider, and the lack of documented patching policies. The article also details the types of sensitive data potentially exposed, including criminal offense and special category information, and notes that while 84,048 individuals were notified, data for only 10,920 was confirmed as staged for exfiltration.

Synthesized by Vypr AI