LIVE · cybersecurity feed
Live wire
breach

Three intrusions at UK criminal records office went undetected for two years

Unread antivirus alerts and an unpatched content management system exposed Britain's ACRO to three separate data breaches, according to a reprimand notice.

zeroday.news ·

The UK's ACRO Criminal Records Office, a national policing unit responsible for sensitive data on the Police National Computer, was subjected to three separate security intrusions over a period of nearly two years, exposing the personal data of thousands of individuals. The incidents, which occurred between July 2021 and June 2023, went largely undetected due to a series of fundamental security failures, according to a reprimand issued by the Information Commissioner’s Office (ICO).

The ICO’s investigation revealed that all three attacks exploited ACRO’s public-facing customer portal, which was built on the Kentico content management system. This system had been running an outdated version since September 2019, despite containing multiple known and publicly documented vulnerabilities for which security fixes were available. ACRO failed to apply these patches, citing confusion among itself, its managed service provider, and its web development supplier regarding responsibility for monitoring and applying updates.

Further compounding the issue, ACRO’s cybersecurity solution, Trend Micro, generated numerous warnings during the attack period, including quarantining four attempts to install the Mimikatz credential-harvesting tool. However, these alerts went unheeded. ACRO informed the ICO that it could not identify any established business process for assessing or handling security alerts, nor could it determine which roles were responsible for reviewing and escalating them. The ICO concluded that timely action on these alerts could have prevented further malicious activity.

The forensic investigation commissioned by ACRO identified three distinct incidents, labeled Group A, Group B, and Group C. The most severe, Group A, involved an attacker maintaining persistent access to ACRO’s website and content management system for approximately seven months, from August 2022 to March 2023. During this time, the attacker conducted reconnaissance and, in February 2023, staged the sensitive data of just under 11,000 people for potential exfiltration. Due to insufficient log retention, ACRO could not definitively confirm whether the data was actually exfiltrated. One of the other incidents involved an SQL injection that exposed employee credentials.

ACRO initially attributed its website downtime in April 2023 to essential maintenance. Following inquiries from the Evening Standard newspaper, the office disclosed that it was responding to a cybersecurity incident. Subsequently, the Medusa ransomware group claimed responsibility for the breach, though no stolen data was ever published on their leak site, leaving open the question of whether an extortion payment was made or the claim was fabricated.

As a precautionary measure, ACRO notified over 84,000 individuals in April 2023 who had submitted applications to the database during the vulnerable period. The ICO received more than 40 formal complaints but did not investigate them as part of its reprimand. The ICO’s reprimand document attributed the failures to ACRO as an institution, without singling out specific individuals or management roles.

A mitigating factor noted by the ICO was that network segmentation ultimately prevented the attackers from moving beyond the compromised web environment into the core policing system. This contributed to the decision to issue a reprimand, which carries no financial penalty. ACRO has since decommissioned the compromised infrastructure, implemented a new security information and event management system, and stated that its new website has undergone rigorous testing.

breachpatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.