Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Researchers Link Suspected Chinese APT to Hack-for-Hire Operations

August 14, 2026

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution

August 14, 2026

RISE with SAP & SAP IDM Sunset: Two Deadlines, One Identity Strategy

August 14, 2026
Facebook X (Twitter) Instagram
Friday, August 14
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»ICO Reprimands Criminal Records Office After 2023 Breach
Cyber Security

ICO Reprimands Criminal Records Office After 2023 Breach

Team-CWDBy Team-CWDAugust 13, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The UK’s data protection watchdog has issued a reprimand to the Criminal Records Office (ACRO) after multiple security failings led to a 2023 data breach which impacted over 10,000 people.

Between August 2022 and March 2023, a hacker gained unauthorized access to ACRO’s website and content management system (CMS), according to the Information Commissioner’s Office (ICO).

However, poor record keeping by ACRO means it remains unclear whether they ever exfiltrated the data on 10,920 victims, the ICO said.

Nevertheless, the breach exposed sensitive information including names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and “highly sensitive criminal offence and special category information.”

Among the dozens of complaints sent to ACRO following the incident, several were from those connected to International Child Protection Certificates, and victims of domestic violence.

Read more on ICO reprimands: ICO Reprimands Metropolitan Police for Data Snafu

The ICO’s ruling of GDPR infringement hinges on two main security failings: poor patch management and insufficient security monitoring.

ACRO’s managed service provider (MSP) took care of OS patches, but not those of the Kentico CMS it used, the ICO revealed. The policing agency’s web development supplier was responsible for applying patches to the CMS, but not identifying when patches were required, it added.

“ACRO itself did not monitor for required security patches, meaning that there was an absence of oversight for this important security control,” the ICO noted.

Second, although ACRO had a Trend Micro solution installed to “detect and quarantine malware,” the alerts it generated on doing so were “not reviewed or acted upon,” the report revealed.

“Had the alerts been investigated by ACRO at the time, and an appropriate response conducted, it is likely that further malicious activity could have been prevented,” it said.

ICO Advice for Other Organizations

In issuing a reprimand, the ICO took into account the fact that ACRO had network segmentation in place, which reduced the blast radius of the attack, and that it took remedial action.

This included “decommissioning the compromised infrastructure, migrating services elsewhere, implementing security monitoring, improving visibility of cyber threats and strengthening network segmentation.”

It is likely the agency escaped a fine due to the ICO’s public sector approach, which limits financial penalties levied on the sector.

“Organizations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyber-attacks are identified, investigated and acted upon promptly,” said ICO group manager for civil and cyber investigations, Jonathan Balmforth.

“The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology.”

The ICO’s advice for other organizations is to:

  • Define who is responsible for identifying, assessing and implementing security updates across all systems
  • Ensure security alerts are actively monitored, investigated and escalated so threats are identified before they become major incidents
  • Get the basics right with effective patch and vulnerability management and regular security testing



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticlevCenter Flaw Exploited Just Five Days After Disclosure
Next Article New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Team-CWD
  • Website

Related Posts

Cyber Security

RISE with SAP & SAP IDM Sunset: Two Deadlines, One Identity Strategy

August 14, 2026
Cyber Security

WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam

August 12, 2026
Cyber Security

Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust

August 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What is it, and how do I get it off my device?

September 11, 2025

A stealthy RAT burrowing deep into Android devices

May 26, 2026

Fixing trivial passwords is as easy as 123456

May 7, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.