The UK's ACRO Criminal Records Office, a national policing unit responsible for sensitive data on the Police National Computer, was subjected to three separate security intrusions over a period of nearly two years, exposing the personal data of thousands of individuals. The incidents, which occurred between July 2021 and June 2023, went largely undetected due to a series of fundamental security failures, according to a reprimand issued by the Information Commissioner’s Office (ICO).
The ICO’s investigation revealed that all three attacks exploited ACRO’s public-facing customer portal, which was built on the Kentico content management system. This system had been running an outdated version since September 2019, despite containing multiple known and publicly documented vulnerabilities for which security fixes were available. ACRO failed to apply these patches, citing confusion among itself, its managed service provider, and its web development supplier regarding responsibility for monitoring and applying updates.
Further compounding the issue, ACRO’s cybersecurity solution, Trend Micro, generated numerous warnings during the attack period, including quarantining four attempts to install the Mimikatz credential-harvesting tool. However, these alerts went unheeded. ACRO informed the ICO that it could not identify any established business process for assessing or handling security alerts, nor could it determine which roles were responsible for reviewing and escalating them. The ICO concluded that timely action on these alerts could have prevented further malicious activity.
The forensic investigation commissioned by ACRO identified three distinct incidents, labeled Group A, Group B, and Group C. The most severe, Group A, involved an attacker maintaining persistent access to ACRO’s website and content management system for approximately seven months, from August 2022 to March 2023. During this time, the attacker conducted reconnaissance and, in February 2023, staged the sensitive data of just under 11,000 people for potential exfiltration. Due to insufficient log retention, ACRO could not definitively confirm whether the data was actually exfiltrated. One of the other incidents involved an SQL injection that exposed employee credentials.
ACRO initially attributed its website downtime in April 2023 to essential maintenance. Following inquiries from the Evening Standard newspaper, the office disclosed that it was responding to a cybersecurity incident. Subsequently, the Medusa ransomware group claimed responsibility for the breach, though no stolen data was ever published on their leak site, leaving open the question of whether an extortion payment was made or the claim was fabricated.
As a precautionary measure, ACRO notified over 84,000 individuals in April 2023 who had submitted applications to the database during the vulnerable period. The ICO received more than 40 formal complaints but did not investigate them as part of its reprimand. The ICO’s reprimand document attributed the failures to ACRO as an institution, without singling out specific individuals or management roles.
A mitigating factor noted by the ICO was that network segmentation ultimately prevented the attackers from moving beyond the compromised web environment into the core policing system. This contributed to the decision to issue a reprimand, which carries no financial penalty. ACRO has since decommissioned the compromised infrastructure, implemented a new security information and event management system, and stated that its new website has undergone rigorous testing.






