UK police data lapse exposed highly sensitive records, watchdog says
Poor patch management and bad monitoring exposed over 10,000 people.

Image by Cybernews.
- The ICO reprimanded ACRO after a hacker accessed its website and Kentico CMS.
- Exposed data may have included names, bank details, biometric data, and highly sensitive criminal offense information.
- More than 10,000 people were affected, and ACRO later notified 84,048 individuals about the potential breach.
- The ICO said poor patch management and ignored security alerts allowed the incident to continue longer.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Information Commissioner’s Office (ICO) has reprimanded the ACRO Criminal Records Office after individual, sensitive information was potentially exposed due to severe cybersecurity failures.
According to the UK’s privacy regulator, between August 2022 and March 2023, a hacker gained unauthorized access to ACRO’s website and Kentico content management system (CMS).
This gave the attacker access to personal and sensitive information, including names, dates of birth, postal addresses, National Insurance numbers, passport and driving license details, bank account information, biometric data, and “highly sensitive criminal offense and special category information,” such as disability, gender reassignment, sexual orientation information, race, and ethnic origin.
Over 10,000 people were affected by the data breach. However, in April 2023, ACRO decided to notify a total of 84,048 people about the incident. As of writing, it remains unclear whether the aforementioned data was exfiltrated.
ACRO received 35 complaints after the incident, including from victims of domestic violence.
In light of the incident, the ICO launched a formal investigation. The privacy watchdog found that ACRO didn’t have the correct organizational measures in place to ensure a proper level of security.
The ICO’s reprimand hinges on two main security failings: poor patch management and insufficient security monitoring.
The Kentico CMS had multiple known vulnerabilities at the time of the incident. ACRO’s managed service provider handled operating system patches and monthly service maintenance, but not the content management system.
“ACRO itself did not monitor for required security patches, meaning that there was an absence of oversight for this important security control,” the reprimand says.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
In addition, ACRO had installed a Trend Micro solution to detect and quarantine malware by scanning files and monitoring system activities. However, the alerts that were generated by the software weren’t reviewed or acted upon.
“Had the alerts been investigated by ACRO at the time, and an appropriate response conducted, it is likely that further malicious activity could have been prevented,” the ICO concludes.
But there’s an upside to this story. During the investigation, researchers noted that ACRO’s network segmentation measures prevented the hacker from moving beyond the compromised environment into core policing systems, thus preventing further harm.
“This case highlights how basic cybersecurity failings can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information,” Jonathan Balmforth, Group Manager Civil and Cyber Investigations at the ICO, says in a statement.
The lessons from this incident are clear. Having the right policies, responsibilities, and oversight arrangements in place is just as important as having the right technolog,- Jonathan Balmforth, Group Manager Civil and Cyber Investigations at the ICO, said.
The ICO recommends that organizations define who’s responsible for identifying, assessing, and implementing security updates across all systems. Furthermore, organizations should immediately act on warning signs before they become major security incidents.
Lastly, organizations should get the basics right, meaning that effective patch management, vulnerability management, and regular security testing should remain some of the most important defenses against cyberattacks.