{
  "id": 666444,
  "title": "Exposed: Woeful security at UK criminal records office that led to sensitive data leak",
  "url": "https://urgent.news/2026/08/12/exposed-woeful-security-at-uk-criminal-records-office-that-led-to",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-12T13:40:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/08/12/exposed-woeful-security-at-uk-criminal-records-office-that-led-to-sensitive-data-leak/5286736"
  },
  "original_language": "en",
  "account": "The UK's Criminal Records Office (ACRO) avoided a fine but received a regulatory reprimand due to security failings that could have exposed sensitive data belonging to nearly 11,000 individuals. ACRO disclosed a cybersecurity incident in April 2023, stating no evidence of compromised data at the time. However, attackers maintained persistent access to ACRO's website and content management system for over seven months, staging sensitive data for possible exfiltration. The Information Commissioner's Office (ICO) found attackers had been in the system since August 2022, exploiting known vulnerabilities due to ACRO's failure to apply patches and hotfixes. ACRO lacked a documented policy for patching Kentico CMS and could not identify roles responsible for reviewing security alerts. Despite an extensive investigation, it remains unclear if the affected data was exfiltrated. ACRO notified 84,048 people about the breach, with 10,920 potentially being at risk of identity theft or financial loss. A spokesperson for ACRO accepted the ICO's findings and highlighted improvements made to bolster security since the incident.",
  "summary": "Nobody patched the CMS or read the alerts, and ACRO still cannot tell whether info was exfiltrated",
  "key_points": [
    "ACRO experienced cybersecurity incident in April 2023",
    "Attackers had persistent access for over seven months",
    "ICO found attackers exploited known vulnerabilities"
  ],
  "editors_take": "The regulatory reprimand against ACRO underscores the consequences of neglecting basic cybersecurity practices, such as patching known vulnerabilities, and highlights the risks of delayed incident detection and response.",
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Exposed: Woeful security at UK criminal records office that led to sensitive data leak",
        "url": "https://urgent.news/2026/08/12/exposed-woeful-security-at-uk-criminal-records-office-that-led-to-668108",
        "published": "2026-08-12T13:40:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}