Breaking
SecurityDeveloping Story

UK records office reprimanded for CMS patch failures

ACRO's unpatched Kentico CMS exposed sensitive data of up to 10,920 people, with alerts unread for months.

··1 hour ago·5 min read
Yellow and green cables are neatly connected.
Photo by Albert Stoynov on Unsplash

For more than seven months, attackers moved freely through the UK's criminal records office website, probing the content management system that held applications for police certificates and child protection checks. Nobody noticed. The alarms had been firing—Trend Micro alerts generated constantly—but no one was assigned to read them. By the time the intrusion was discovered in March 2023, it was too late to know if anyone's data had actually been stolen.

The UK's Information Commissioner's Office (ICO) has now issued a reprimand to ACRO, the body that processes criminal record checks, after an investigation found a cascade of security failures: an unpatched CMS, ambiguous patching responsibilities, and a complete absence of alert monitoring. The regulator opted not to fine ACRO, citing its public-sector status, but the findings paint a picture of systemic neglect.

Breach uncovered by accident

The ICO said the breach was uncovered in March 2023 only because ACRO was investigating a separate intrusion. While looking into an SQL injection attack that compromised 15 sets of credentials—most belonging to ACRO staff—investigators stumbled upon evidence of earlier, distinct compromises dating back to July 8, 2021.

Those incidents fell into three categories, according to the ICO. Some did not affect personal data, while others exposed only a small number of account credentials. The most serious involved ACRO's website and its Kentico content management system. That intrusion began on August 5, 2022, and the attackers maintained persistent access, undetected, until March 14, 2023.

ACRO had initially disclosed a "cybersecurity incident" in April 2023, saying at the time that it had no evidence to suggest any data was compromised. That disclosure came a month after the intrusion had been discovered.

Patching duties in limbo

The ICO found that ACRO ran version 12.0.0 of Kentico CMS from September 2019 until March 2023 without applying any of the patches and hotfixes released during that period, leaving known vulnerabilities unresolved.

The blame, according to the ICO, lay partly with poor communication between ACRO and its managed service provider. The supplier did not learn that patching was its responsibility until February 2020 and continued to assume it was not required to monitor actively for security updates.

The ambiguity around who was accountable for identifying necessary Kentico CMS patches created a gap where patches and hotfixes were missed, which ultimately left ACRO's website vulnerable.

— ICO statement

ACRO also lacked a documented policy covering patching Kentico CMS, and could not demonstrate how vulnerabilities were identified or prioritized.

Alerts fired, nobody listened

ACRO's Trend Micro antivirus generated alerts, but nobody appears to have been minding them. The records office told the ICO that, for reasons redacted from the postmortem, it was "unable to establish what business processes existed for the assessment or handling of security alerts at the relevant time."

It also could not identify which roles were responsible for reviewing these alerts at the time, ultimately resulting in them going unread. The ICO's report highlights this as a critical failure, as the alerts could have provided early warning of the intrusion.

Staged for exfiltration

ACRO's poor logging meant that, despite an extensive investigation by a third-party cybersecurity firm, it remains impossible to determine whether the affected data was actually exfiltrated. Investigators did establish that the attackers staged the data for possible exfiltration between February 15 and 16, 2023.

The potentially exposed material included:

  • Police Certificate Applications
  • Subject Access Request (SAR) forms and International Child Protection Certificate forms
  • Names, dates of birth, and addresses
  • National Insurance numbers
  • Passport and driving licence details
  • Bank account information
  • Biometric data
  • Highly sensitive criminal offence and special category information

ACRO notified 84,048 people of the breach, although investigators later determined that data relating to no more than 10,920 individuals had potentially been staged for exfiltration.

Victims speak out

Of those potentially affected, ACRO received 35 formal complaints citing personal distress and concern about the risk of identity theft and financial loss, according to the ICO's reprimand document.

The ICO noted: "Complainants included those connected to Police Certificates, International Child Protection Certificates, and victims of domestic violence." The ICO itself also received six complaints citing similar concerns.

Segmentation as saving grace

ACRO's saving grace was its network segmentation, which prevented the attackers from straying beyond the CMS into other systems, the ICO noted. This containment likely limited the scope of the compromise, even though the full extent of the data exposure remains unknown.

Since the attack was discovered, ACRO has made a number of improvements to its security, including decommissioning the compromised infrastructure (though not until June 2023), implementing a SIEM, improving visibility, monitoring, and network segmentation, hardening systems, and migrating to Salesforce Experience Cloud.

ICO: accountability is key

Jonathan Balmforth, group manager of civil and cyber investigations at the ICO, said: "This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information.

"Organizations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyberattacks are identified, investigated and acted upon promptly.

"The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology.

"We welcome the improvements ACRO has made since these incidents. We hope other organizations will use this case as an opportunity to review their own processes and responses to ensure personal information remains properly protected."

ACRO accepts findings

ACRO welcomed the reprimand and highlighted the steps it has taken since to bolster its security. A spokesperson told The Register: "Since the cybersecurity incident was identified in March 2023, we have worked hard to strengthen our systems and safeguards.

"In particular, we immediately took the previous website offline and subsequently decommissioned it. We also took steps to protect customers, including making sure anyone potentially affected was informed at the earliest possible stage."

They went on: "We accept the ICO's findings of the infringements. We are grateful for the recognition from the Information Commissioner of the multiple remedial steps ACRO has taken in light of this incident and are committed to maintaining high standards of data protection and information security in future."

Why it matters

This case shows how basic hygiene failures—unpatched software, unread alerts, unclear ownership—can leave organizations blind to intrusions for months, even when they handle some of the most sensitive data imaginable. For any organization running a CMS or relying on managed service providers, the lesson is to document exactly who patches what, and to ensure someone is actually watching the security dashboard. The fact that ACRO still cannot say whether data was stolen underscores that logging isn't just a technical nicety; it's essential for knowing what happened after a breach. As the ICO warned, policies and oversight are just as important as technology—and without them, a breach can go unnoticed until it's too late.

#acro#ico#data breach#kentico cms#patching#uk

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories