England: ACRO reprimanded following cyber security failings
The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office after cyber security failings left the personal information of up to ten thousand people, including some individuals’ sensitive data, potentially exposed.
The ICO’s investigation found that between August 2022 and March 2023, a hacker gained unauthorised access to ACRO’s website and content management system (CMS). The attacker was able to stage personal information to be stolen, although ACRO could not conclusively determine whether the information was removed from its systems.
The investigation found that up to 10,920 people may have been affected. The data potentially exposed included names, dates of birth, addresses, national insurance numbers, passport and driving licence details, bank account information, biometric data, and highly sensitive criminal offence and special category information. Those affected included applicants for police certificates and international child protection certificates, subject access request applicants, and third parties connected to those applications.
Jonathan Balmforth, ICO’s group manager - civil and cyber Investigations, said: “This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organisations process large volumes of highly sensitive personal information.
“Organisations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyber-attacks are identified, investigated and acted upon promptly.
“The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology.
“We welcome the improvements ACRO has made since these incidents. We hope other organisations will use this case as an opportunity to review their own processes and responses to ensure personal information remains properly protected.”
The ICO found ACRO had engaged third-party providers to deliver certain security services, including patch management. However, ACRO did not ensure clear responsibility for identifying and monitoring critical CMS security updates, failed to maintain an effective patch management process, and did not adequately investigate security alerts that could have identified the hacker’s activity earlier.
In deciding to issue a reprimand, the ICO took into account a number of mitigating factors. Network segmentation prevented the hacker from moving beyond the compromised website environment into core systems, reducing the potential scale of harm. The ICO additionally welcomed the remedial action taken by ACRO following the incident, including decommissioning the compromised infrastructure, migrating services elsewhere, implementing security monitoring, improving visibility of cyber threats and strengthening network segmentation.



