Britain’s criminal records office has escaped a fine for security failures that potentially exposed sensitive data belonging to nearly 11,000 people. The Information Commissioner’s Office issued a reprimand to ACRO after finding attackers held persistent access to its website and content management system for more than seven months.
The intrusion began August 5, 2022 and went undetected until March 14, 2023. Investigators uncovered it only while probing a separate SQL injection attack that compromised 15 sets of credentials, most belonging to staff. ACRO ran version 12.0.0 of Kentico CMS from September 2019 to March 2023 without applying patches, the ICO found, blaming unclear responsibility between the office and its managed service provider.
Trend Micro antivirus alerts went unread because no one could identify which roles were responsible for reviewing them. Poor logging means it remains impossible to determine whether data was actually exfiltrated, though investigators established that attackers staged material for possible exfiltration between February 15 and 16, 2023.
Potentially exposed records include Police Certificate Applications, Subject Access Request forms, International Child Protection Certificate forms, names, and dates of birth. The ICO said monetary penalties are reserved for the worst offenses, and reprimands are often used for public sector bodies to avoid draining public funds.
