Summary
- An attacker had unauthorised access to ACRO’s website and content management system between August 2022 and March 2023.
- Up to 10,920 people may have been affected, with biometric, financial, identity, and criminal-record information among the data at risk.
- The ICO found unclear responsibility for security updates, ineffective patch management, and inadequate investigation of security alerts.
ACRO Criminal Records Office has been reprimanded by the Information Commissioner’s Office after failures in patching, monitoring, and supplier oversight allowed an attacker to remain inside its website environment for months while highly sensitive personal information was placed at risk.
The ICO found that a hacker gained unauthorised access to ACRO’s website and content management system between August 2022 and March 2023, creating an opportunity to stage personal information for theft. ACRO could not determine conclusively whether the information was removed from its systems, although the regulator found that as many as 10,920 people may have been affected.
The potential exposure included names, dates of birth, addresses, National Insurance numbers, passport and driving-licence details, bank information, biometric data, criminal-offence records, and other special-category information. Applicants for Police Certificates and International Child Protection Certificates were among those affected, alongside subject-access applicants and third parties connected with applications.
The regulator’s findings focus less on an exotic attack technique than on ordinary security management. ACRO had contracted third parties to provide some security services, including patch management, but responsibility for identifying and monitoring critical updates to the content management system was not sufficiently clear, while security alerts that could have revealed the attacker earlier were not adequately investigated.
Outsourcing did not transfer accountability
The case illustrates a recurring weakness in managed technology environments: a supplier can perform security work without the customer ceasing to own the consequences. Patch management is particularly exposed to blurred responsibility because identifying an update, assessing its importance, testing it, approving downtime, applying the change, and confirming success can involve several internal teams and external providers.
If ownership of one step is assumed rather than defined, a vulnerability can remain open even though everyone involved believes another party is responsible for closing it. The ICO’s findings against ACRO centre on that gap, with external provision of security services failing to produce a sufficiently clear process for critical CMS updates.
Monitoring broke down alongside patching. The regulator found that security alerts were not adequately investigated, reducing the chance of detecting the compromise earlier. Technology for identifying suspicious behaviour therefore existed within a governance environment that did not consistently convert warnings into action.
The distinction becomes particularly consequential where sensitive public-sector information is involved. ACRO processes records that may be required for overseas employment, immigration, safeguarding, and access requests, while some of the information involved can be difficult or impossible to replace if compromised.
Segmentation limited the potential damage
The ICO did identify controls that reduced the consequences of the incident. Network segmentation prevented the attacker from moving beyond the compromised website environment into ACRO’s core systems, limiting the potential scope even though information within the affected environment remained at risk.
That mitigation provides a useful counterpoint to the failures elsewhere because security architecture rarely depends on one control working perfectly. Segmentation is intended to prevent one compromised component becoming a route through an entire organisation, and in ACRO’s case the regulator considered that containment when deciding on a reprimand.
ACRO has since decommissioned the affected infrastructure, migrated services elsewhere, introduced security monitoring, improved visibility of cyber threats, and strengthened network segmentation. Those measures address parts of the environment highlighted by the investigation, although they came after the attacker had already maintained access.
The ICO chose a reprimand rather than announcing a financial penalty, while using the case to tell organisations to clarify responsibility for security updates, investigate alerts, and maintain effective patch and vulnerability management.
Public services depend on routine security work
Large cyber incidents are often described through the sophistication of attackers, but operational failures can be much more mundane. Content management systems need updating, alerts need owners, suppliers need measurable responsibilities, and somebody inside the organisation must be able to verify that the resulting controls are working.
Those activities are harder to sustain than a one-off technology purchase because they depend on recurring processes. A patching policy written once does not apply an update, while a monitoring platform does not investigate its own alerts unless the operating model assigns responsibility and time to do so.
Public-sector organisations carry an additional burden because much of the information they hold is collected as part of statutory, policing, welfare, health, or administrative services rather than through a discretionary commercial relationship.
ACRO’s incident consequently provides a case study in the difference between buying security services and governing them. The attacker did not need to compromise every layer of the organisation to create serious risk; prolonged access to a web environment containing sensitive information was sufficient.
Segmentation prevented the compromise from travelling further, but the ICO’s reprimand returns responsibility to the organisation to ensure that security work is not merely contracted out but demonstrably performed, monitored, and owned.












