ACRO reprimanded after cyber security failings
The Information Commissioner’s Office (ICO) has reprimanded the ACRO Criminal Records Office after cyber security failings potentially exposed the personal information of more than 10,000 people.
The ICO found that a hacker gained unauthorised access to ACRO’s website and content management system between August 2022 and March 2023.
The attacker was able to stage personal information for removal, although ACRO was unable to establish conclusively whether any information was actually taken from its systems.
Up to 10,920 people may have been affected. The information potentially exposed included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information and biometric data, as well as highly sensitive criminal offence and other special category information.
Those affected included applicants for Police Certificates and International Child Protection Certificates, subject access request applicants and third parties connected to those applications.
The ICO’s investigation found that ACRO used third-party providers for some security services, including patch management. However, it did not ensure there was clear responsibility for identifying and monitoring critical security updates for its CMS, while its patch management process was also found to be ineffective.
The organisation also failed to adequately investigate security alerts which could have identified the hacker’s activity at an earlier stage.
Jonathan Balmforth, ICO group manager for civil and cyber investigations, said the case demonstrated how “basic cyber security failings” could create significant risks for organisations handling large volumes of sensitive personal information.
He said clear accountability for identifying, assessing and applying security updates was essential, alongside effective monitoring to ensure warning signs of cyber attacks were acted upon promptly.
The ICO took into account a number of mitigating factors when deciding to issue a reprimand rather than take more serious enforcement action.
Network segmentation had prevented the attacker from moving beyond the compromised website environment into ACRO’s core systems, limiting the potential scale of the incident.
The ICO also welcomed remedial action taken by ACRO, including decommissioning the compromised infrastructure, migrating services, introducing security monitoring, improving visibility of cyber threats and strengthening network segmentation.
The regulator said the incident provided lessons for other organisations, highlighting the importance of clearly defining security responsibilities across internal teams and suppliers, actively investigating security alerts and maintaining effective patch and vulnerability management processes.


