Exposed: Woeful security at UK criminal records office that led to sensitive data leak

← Back to the feed

Exposed: Woeful security at UK criminal records office that led to sensitive data leak

The Register · 2 hours ago

The UK criminal records office, ACRO, has been formally reprimanded by the Information Commissioner’s Office after security failures may have exposed sensitive information relating to nearly 11,000 people. Attackers retained access to ACRO’s website and content management system for more than seven months, and investigators found data had been prepared for possible extraction, although ACRO still cannot determine whether it was actually taken.

The intrusion ran from 5 August 2022 to 14 March 2023 and was discovered only during an investigation into a separate SQL injection attack affecting 15 credential sets. ACRO had operated an unpatched Kentico CMS version since 2019, with unclear responsibility for patching between it and a service provider, no documented patching policy, and apparently unmanaged antivirus alerts. The ICO chose a reprimand rather than a fine, noting that financial penalties are generally reserved for the most serious UK GDPR breaches and can reduce public-sector funds.

  • ACRO left sensitive criminal-records data potentially exposed for months.
  • Unpatched software and unclear responsibilities enabled the breach.
  • ACRO cannot confirm whether attackers exfiltrated the data.

UK World

Read the full article at the source →