Summary
- The ICO says up to 10,920 people may have had personal information staged for exfiltration during the ACRO compromise.
- Investigators found weak patch management, unclear responsibility for critical updates, and security alerts that were not adequately investigated.
- Network segmentation prevented movement into core systems and reduced the potential scale of the incident.
The Information Commissioner’s Office has reprimanded ACRO Criminal Records Office after finding that patch-management and monitoring failures contributed to a prolonged compromise involving highly sensitive personal information.
The regulator said an attacker maintained unauthorised access to ACRO Criminal Records Office’s website and content-management environment between August 2022 and March 2023. Information belonging to as many as 10,920 people was staged for possible exfiltration, although ACRO was unable to determine conclusively whether the data left its systems.
The potentially exposed information included names, dates of birth, addresses, National Insurance numbers, passport and driving-licence details, bank account information, biometric data, criminal-offence information, and other special-category data.
The affected population included people applying for Police Certificates and International Child Protection Certificates, subject-access applicants, and third parties connected with those applications.
The Information Commissioner’s Office found that ACRO had contracted third-party providers for some security functions, including patch management, but had not established clear responsibility for identifying and monitoring critical security updates affecting its content-management system.
Investigators also found that ACRO did not maintain an effective patching process and failed to investigate security alerts that could have exposed the attacker’s activity earlier. The regulator’s findings place governance around outsourced security controls alongside the technical failures themselves.
Delegating a function to a supplier does not remove the need to know who owns the resulting control. Patch management, monitoring, and vulnerability handling depend on decisions about who tracks vendor advisories, who determines urgency, who tests changes, who authorises deployment, and who confirms that remediation has actually taken place. Ambiguity between an organisation and a service provider can leave each side assuming that the other has acted.
The ACRO incident also provides a counter-example in the form of a control that did work. Network segmentation prevented the attacker from moving beyond the compromised website environment into core systems, according to the ICO, reducing the potential scale of the breach.
That containment limited the incident but did not resolve the uncertainty around the data itself. Where logging and monitoring are insufficient, an organisation may be unable to determine whether information staged by an intruder was ultimately removed. That uncertainty carries its own operational and regulatory consequences, particularly where criminal records, identity documents, financial information, and biometric data are involved.
ACRO has since decommissioned the compromised infrastructure and migrated services elsewhere. The regulator also noted additional monitoring, better visibility of cyber threats, stronger system hardening, and improved network segmentation among the remediation measures taken after the incident.
The reprimand sits within the ICO’s corrective powers under UK data-protection law rather than functioning as a technical vulnerability notice. Its findings focus heavily on whether the organisation maintained appropriate technical and organisational measures, including ongoing confidentiality, resilience, testing, and oversight.
The case therefore reaches beyond the particular content-management system that was compromised. It demonstrates how accountability gaps around routine controls can persist for long periods even where specialist suppliers are already engaged, and how segmentation can limit damage when preventive and detective controls fail.
ACRO’s remediation reduces the relevance of the original infrastructure to current operations, but the regulator’s findings leave a broader governance record: critical updates were not clearly owned, alerts were not adequately investigated, and the organisation could not conclusively establish whether some of its most sensitive data had been exfiltrated.




