Exposed: Woeful security at UK criminal records office that led to sensitive data leak
Nobody patched the CMS or read the alerts, and ACRO still cannot tell whether info was exfiltrated
The UK's Criminal Records Office (ACRO) recently faced criticism for its inadequate security measures, which potentially exposed sensitive data belonging to nearly 11,000 individuals. Although ACRO disclosed the cybersecurity incident in April 2023 and claimed no data was compromised, it later revealed attackers had maintained persistent access to their website and content management system for over seven months.
The Information Commissioner's Office (ICO) reprimanded ACRO instead of imposing a fine, finding that the breach went undetected because ACRO was investigating a separate intrusion at the time.
Upon investigating an SQL injection attack that compromised staff credentials, ICO investigators discovered evidence of separate intrusions dating back to July 8, 2021. These breaches were categorized into three groups: some had no impact on personal data, others exposed only a few account credentials, and the most serious involved ACRO's website and Kentico content management system. The attackers exploited known vulnerabilities due to ACRO's failure to apply necessary patches, leaving their website exposed.
ACRO's network segmentation prevented attackers from accessing other systems beyond the CMS, but they had staged the data for possible exfiltration between February 15 and 16, 2023. The exposed information included police certificate applications, SAR forms, International Child Protection Certificate forms, personal details, bank account information, biometric data, and highly sensitive criminal offence details.
ACRO notified 84,048 people of the breach, with only 10,920 individuals potentially having data staged for exfiltration.
ACRO acknowledged the ICO's findings and highlighted the steps taken to improve security since the incident, including decommissioning the compromised infrastructure, implementing a SIEM, improving monitoring and network segmentation, hardening systems, and migrating to Salesforce Experience Cloud. The ICO emphasized the importance of clear accountability for security updates, effective monitoring, and proper policies to protect personal information adequately.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.