UK records office reprimanded for CMS patch failures
ACRO's unpatched Kentico CMS exposed sensitive data of up to 10,920 people, with alerts unread for months.
For more than seven months, attackers moved freely through the UK's criminal records office website, probing the content management system that held applications for police certificates and child protection checks. Nobody noticed. The alarms had been firing—Trend Micro alerts generated constantly—but no one was assigned to read them. By the time the intrusion was discovered in March 2023, it was too late to know if anyone's data had actually been stolen.
The UK's Information Commissioner's Office (ICO) has now issued a reprimand to ACRO, the body that processes criminal record checks, after an investigation found a cascade of security failures: an unpatched CMS, ambiguous patching responsibilities, and a complete absence of alert monitoring. The regulator opted not to fine ACRO, citing its public-sector status, but the findings paint a picture of systemic neglect.
Breach uncovered by accident
The ICO said the breach was uncovered in March 2023 only because ACRO was investigating a separate intrusion. While looking into an SQL injection attack that compromised 15 sets of credentials—most belonging to ACRO staff—investigators stumbled upon evidence of earlier, distinct compromises dating back to July 8, 2021.
Those incidents fell into three categories, according to the ICO. Some did not affect personal data, while others exposed only a small number of account credentials. The most serious involved ACRO's website and its Kentico content management system. That intrusion began on August 5, 2022, and the attackers maintained persistent access, undetected, until March 14, 2023.
ACRO had initially disclosed a "cybersecurity incident" in April 2023, saying at the time that it had no evidence to suggest any data was compromised. That disclosure came a month after the intrusion had been discovered.
Patching duties in limbo
The ICO found that ACRO ran version 12.0.0 of Kentico CMS from September 2019 until March 2023 without applying any of the patches and hotfixes released during that period, leaving known vulnerabilities unresolved.
The blame, according to the ICO, lay partly with poor communication between ACRO and its managed service provider. The supplier did not learn that patching was its responsibility until February 2020 and continued to assume it was not required to monitor actively for security updates.
The ambiguity around who was accountable for identifying necessary Kentico CMS patches created a gap where patches and hotfixes were missed, which ultimately left ACRO's website vulnerable.
— ICO statement
ACRO also lacked a documented policy covering patching Kentico CMS, and could not demonstrate how vulnerabilities were identified or prioritized.
Alerts fired, nobody listened
ACRO's Trend Micro antivirus generated alerts, but nobody appears to have been minding them. The records office told the ICO that, for reasons redacted from the postmortem, it was "unable to establish what business processes existed for the assessment or handling of security alerts at the relevant time."
It also could not identify which roles were responsible for reviewing these alerts at the time, ultimately resulting in them going unread. The ICO's report highlights this as a critical failure, as the alerts could have provided early warning of the intrusion.
Staged for exfiltration
ACRO's poor logging meant that, despite an extensive investigation by a third-party cybersecurity firm, it remains impossible to determine whether the affected data was actually exfiltrated. Investigators did establish that the attackers staged the data for possible exfiltration between February 15 and 16, 2023.
The potentially exposed material included:
- Police Certificate Applications
- Subject Access Request (SAR) forms and International Child Protection Certificate forms
- Names, dates of birth, and addresses
- National Insurance numbers
- Passport and driving licence details
- Bank account information
- Biometric data
- Highly sensitive criminal offence and special category information
ACRO notified 84,048 people of the breach, although investigators later determined that data relating to no more than 10,920 individuals had potentially been staged for exfiltration.
Victims speak out
Of those potentially affected, ACRO received 35 formal complaints citing personal distress and concern about the risk of identity theft and financial loss, according to the ICO's reprimand document.
The ICO noted: "Complainants included those connected to Police Certificates, International Child Protection Certificates, and victims of domestic violence." The ICO itself also received six complaints citing similar concerns.
Segmentation as saving grace
ACRO's saving grace was its network segmentation, which prevented the attackers from straying beyond the CMS into other systems, the ICO noted. This containment likely limited the scope of the compromise, even though the full extent of the data exposure remains unknown.
Since the attack was discovered, ACRO has made a number of improvements to its security, including decommissioning the compromised infrastructure (though not until June 2023), implementing a SIEM, improving visibility, monitoring, and network segmentation, hardening systems, and migrating to Salesforce Experience Cloud.
ICO: accountability is key
Jonathan Balmforth, group manager of civil and cyber investigations at the ICO, said: "This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information.
"Organizations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyberattacks are identified, investigated and acted upon promptly.
"The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology.
"We welcome the improvements ACRO has made since these incidents. We hope other organizations will use this case as an opportunity to review their own processes and responses to ensure personal information remains properly protected."
ACRO accepts findings
ACRO welcomed the reprimand and highlighted the steps it has taken since to bolster its security. A spokesperson told The Register: "Since the cybersecurity incident was identified in March 2023, we have worked hard to strengthen our systems and safeguards.
"In particular, we immediately took the previous website offline and subsequently decommissioned it. We also took steps to protect customers, including making sure anyone potentially affected was informed at the earliest possible stage."
They went on: "We accept the ICO's findings of the infringements. We are grateful for the recognition from the Information Commissioner of the multiple remedial steps ACRO has taken in light of this incident and are committed to maintaining high standards of data protection and information security in future."
Why it matters
This case shows how basic hygiene failures—unpatched software, unread alerts, unclear ownership—can leave organizations blind to intrusions for months, even when they handle some of the most sensitive data imaginable. For any organization running a CMS or relying on managed service providers, the lesson is to document exactly who patches what, and to ensure someone is actually watching the security dashboard. The fact that ACRO still cannot say whether data was stolen underscores that logging isn't just a technical nicety; it's essential for knowing what happened after a breach. As the ICO warned, policies and oversight are just as important as technology—and without them, a breach can go unnoticed until it's too late.
Sources
- The Register Original source
Continue Reading
Fake Hires: The Identity Gap in Onboarding
State and FBI warnings highlight how fake remote workers bypass hiring controls to gain network access.
Stealthy Guest-Access Attacks Hit Salesforce, ServiceNow
Researchers uncover 'City-Forum' campaign using a custom toolset to exploit unauthenticated guest access in Salesforce and ServiceNow.
Fake CCleaner sites push Chrome spyware
Malwarebytes finds fake CCleaner downloads installing GhostDesk Chrome extension for credential theft and surveillance.