Info Gov

The Information Commissioner's Office (ICO) has urged organisations to strengthen “patching and security monitoring processes” after cyber security failings at ACRO Criminal Records Office left the personal information of up to ten-thousand people, including some individuals’ sensitive data, potentially exposed.

An ICO investigation found that between August 2022 and March 2023, a hacker gained unauthorised access to ACRO’s website and content management system (CMS).

The attacker was then able to stage personal information to be stolen, although ACRO could not conclusively determine whether the information was removed from its systems, the ICO said.

The investigation found that up to 10,920 people may have been affected.

The ICO said: “The data potentially exposed included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and highly sensitive criminal offence and special category information.

“Those affected included applicants for Police Certificates and International Child Protection Certificates, subject access request applicants, and third parties connected to those applications.”

Concluding the investigation, the watchdog found that ACRO had engaged third-party providers to deliver certain security services, including patch management.

However, ACRO “did not ensure clear responsibility for identifying and monitoring critical CMS security updates, failed to maintain an effective patch management process, and did not adequately investigate security alerts that could have identified the hacker’s activity earlier”.

In deciding to issue a reprimand, the ICO took into account a number of mitigating factors.

It noted: “Network segmentation prevented the hacker from moving beyond the compromised website environment into core systems, reducing the potential scale of harm”.

The ICO additionally welcomed remedial action taken by ACRO following the incident, including decommissioning the compromised infrastructure, migrating services elsewhere, implementing security monitoring, improving visibility of cyber threats and strengthening network segmentation.

The ICO issued the following advice for other organisations:

• “Make accountability clear: Define who is responsible for identifying, assessing and implementing security updates across all systems and suppliers.
• Act on warning signs: Ensure security alerts are actively monitored, investigated and escalated so threats are identified before they become major incidents.
• Get the basics right: Effective patch management, vulnerability management and regular security testing remain some of the most important defences against cyber attacks.”

Jonathan Balmforth, ICO’s Group Manager - Civil and Cyber Investigations, said: “This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organisations process large volumes of highly sensitive personal information.

"Organisations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyber-attacks are identified, investigated and acted upon promptly.

"The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology.”

He added: "We welcome the improvements ACRO has made since these incidents. We hope other organisations will use this case as an opportunity to review their own processes and responses to ensure personal information remains properly protected."

A spokesperson for ACRO said: “Since the cyber security incident was identified in March 2023, we have worked hard to strengthen our systems and safeguards.

“In particular, we immediately took the previous website offline and subsequently decommissioned it. We also took steps to protect customers, including making sure anyone potentially affected was informed at the earliest possible stage.

“We now have a new website that has been rigorously tested and migrated to the Salesforce Experience Cloud. We have implemented Security Information and Event Management (SIEM), and enhanced visibility and monitoring. These actions have ensured a robust and secure platform.

“We accept the ICO's findings of the infringements. We are grateful for the recognition from the Information Commissioner of the multiple remedial steps ACRO has taken in light of this incident and are committed to maintaining high standards of data protection and information security in future.”

Also in this section

Sep 11, 2026

Anthropic discloses fourth incident of AI model attacking real systems and hands investigation to independent evaluation organisation

Anthropic has published details of four incidents in which its Claude models gained unauthorised access to real third-party systems during cybersecurity evaluations, downloading and modifying user records at a real company, reading the personal information of an individual, harvesting credentials and accessing a security vendor's live database, after the test environments were mistakenly…
Sep 10, 2026

Welsh environmental watchdog hit by data breach

Environmental regulator Natural Resources Wales (NRW) has reported itself to the Information Commissioner's Office after a data breach saw personal details of staff made public.
Aug 24, 2026

Ministers seek power to ban tech risky vendors from critical sectors and bar recipients from discussing the order

The government has tabled amendments to the Cyber Security and Resilience (Network and Information Systems) Bill that would allow the Secretary of State to direct operators of essential services, data centres, managed service providers and other designated organisations to stop buying from, restrict the use of, or remove and disable products from a named vendor on national security grounds, with…
Aug 06, 2026

AI agents sent malicious files to real developers and planted prompt injections in unmonitored test: AISI

The AI Security Institute (AISI) has published an incident report disclosing that AI agents under evaluation in its research environment took sustained, unsanctioned action against real people and organisations on the live internet, including researching the human maintainers of an open-source project, creating fake online identities to pressure one of them into approving malicious code, and…
Aug 05, 2026

Third AI platform goes rogue during cyber testing

The AI Security Institute (AISI) has reveaked a security incident in which AI agents being evaluated for their cyber capabilities took sustained, unsanctioned action directed at real people and organisations, including an attempted supply-chain attack on a publicly used open-source software project.

InfoGov Masthead Newsletter 800