Urgent.News

What's breaking now, across thousands of outlets.

Tech

Exposed: Woeful security at UK criminal records office that led to sensitive data leak

Nobody patched the CMS or read the alerts, and ACRO still cannot tell whether info was exfiltrated

Exposed: Woeful security at UK criminal records office that led to sensitive data leak

The UK's Criminal Records Office (ACRO) recently faced criticism for its inadequate security measures, which potentially exposed sensitive data belonging to nearly 11,000 individuals. Although ACRO disclosed the cybersecurity incident in April 2023 and claimed no data was compromised, it later revealed attackers had maintained persistent access to their website and content management system for over seven months.

The Information Commissioner's Office (ICO) reprimanded ACRO instead of imposing a fine, finding that the breach went undetected because ACRO was investigating a separate intrusion at the time.

Upon investigating an SQL injection attack that compromised staff credentials, ICO investigators discovered evidence of separate intrusions dating back to July 8, 2021. These breaches were categorized into three groups: some had no impact on personal data, others exposed only a few account credentials, and the most serious involved ACRO's website and Kentico content management system. The attackers exploited known vulnerabilities due to ACRO's failure to apply necessary patches, leaving their website exposed.

ACRO's network segmentation prevented attackers from accessing other systems beyond the CMS, but they had staged the data for possible exfiltration between February 15 and 16, 2023. The exposed information included police certificate applications, SAR forms, International Child Protection Certificate forms, personal details, bank account information, biometric data, and highly sensitive criminal offence details.

ACRO notified 84,048 people of the breach, with only 10,920 individuals potentially having data staged for exfiltration.

ACRO acknowledged the ICO's findings and highlighted the steps taken to improve security since the incident, including decommissioning the compromised infrastructure, implementing a SIEM, improving monitoring and network segmentation, hardening systems, and migrating to Salesforce Experience Cloud. The ICO emphasized the importance of clear accountability for security updates, effective monitoring, and proper policies to protect personal information adequately.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

Faked photos could be shown up by new iPhone feature

Apple aims to make it possible to prove that a photo was taken on your iPhone and, presumably, not subsequently altered. The latest developer beta of iOS 27 has an unusual number of new features for…

  • New iOS 27 feature called Apple Reference Image
  • Authenticates photos taken by iPhone camera
  • Relies on specific conditions to prove origin

More from Wednesday 12 August →