Full Report
What HappenedOn 7 August 2026, the UK Information Commissioner's Office (ICO) disclosed that between July 2021 and June 2023, the ACRO Criminal Records Office suffered three separate compromises involving its customer portal website (acro.police.uk).ACRO is a national police unit providing public services such as issuing Police Certificates, International Child Protection Certificates, and processing Subject Access Requests.In March 2023, ACRO was notified about an SQL injection attack that reportedly exposed 15 sets of credentials, the majority of which belonged to its employees.A subsequent forensic investigation uncovered long-term threat actor activity within the website's environment, spanning from 9 July 2021 to 22 June 2023.The website was built on the Kentico CMS and was running version 12.0.0 between September 2019 and March 2023. This version had multiple known vulnerabilities at the time of the incident, but suffered from ambiguity around who was accountable for patching led to missed hotfixes and updates.Between 15 and 16 February 2023, an unknown threat actor staged personal data for exfiltration, which included Police Certificate Applications, Subject Access Request (SAR) forms, and International Child Protection Certificate forms.Due to insufficient log retention, ACRO could not definitively determine if the data was successfully exfiltrated. A maximum of 10,920 data subjects had their data staged, but ACRO ultimately notified 84,048 data subjects on a precautionary basis in April 2023.Notably, on 23 February 2023, the ICO learned that ACRO's Trend Micro antivirus software detected and quarantined four attempts to install the well-known credential harvesting tool Mimikatz. However, because ACRO operated without a documented patching policy and lacked a structured process for analyzing security alerts, these warnings were never reviewed or acted upon.Analyst CommentThe Information Commissioner's Office (ICO) reprimand against the ACRO underscores the persistent issue within many organisations of a breakdown in basic IT governance and accountability. The fact that a threat actor was able to operate within the environment for nearly two years highlights systemic failures in both vulnerability management and security monitoring. Running an outdated content management system with known vulnerabilities for several years is a critical oversight. The ambiguity surrounding patching responsibilities created a dangerous blind spot that adversaries successfully exploited. Further, the failure to act on critical security alerts is also a classic breakdown in the incident response chain. While the deployed Trend Micro antivirus successfully detected and quarantined a known threat, the alerts were ultimately ignored. Security tools are only as effective as the teams monitoring and responding to them. Without a structured review process, even the most sophisticated detection capabilities fall flat.It is important to note, however, that while private sector organisations will receive a hefty fine for data protection offences, public sector organisations like ACRO receive a public reprimand from the ICO rather than receive a fine that confiscates public funds.At the time of writing, the data has not yet appeared on any cybercrime forums or underground chat channels. The use of an open source tool like Mimikatz combined with SQL injection attacks indicates a likely opportunistic adversary rather than a stealthy cyber-espionage operation. However, both cybercriminal and nation state groups are known for opportunistic attacks. Current attribution for who or what was responsible this breach remains uncertain from an open source intelligence (OSINT) perspective.On a positive note, the ICO highlighted that ACRO’s network segmentation effectively prevented the threat actor from pivoting from the compromised web environment into core policing systems. This containment significantly reduced the scale of harm and demonstrates the immense value of architectural defense-in-depth strategies. Following the breach, ACRO has migrated its portal to the Salesforce Experience Cloud for automated patching and hotfixes and implemented a Security Information and Event Management (SIEM) system to improve visibility.Defensive TakeawaysEstablish Clear Accountability for Patching: Organisations must have a documented patching policy with clearly defined ownership, especially for public-facing web applications and Content Management Systems (CMS). Ambiguity in IT governance directly leads to unpatched vulnerabilities which then get exploited.Implement Structured Alert Monitoring: Deploying antivirus or Endpoint Detection and Response (EDR) solutions alone is insufficient if alerts are not actively monitored and investigated. It is recommended to establish either structured internal processes or an outsourced 24/7 Managed Detection and Response (MDR) or SOC service to review and respond to critical security alerts promptly.Maintain Robust Network Segmentation: Ensure that public-facing web infrastructure is strictly segmented from internal corporate networks and core operational systems. As demonstrated in this incident, strict segmentation is a crucial control for stopping an attacker's lateral movement.Ensure Adequate Log Retention: Insufficient logging severely hinders incident response and forensic investigations. Implement comprehensive logging policies and utilise a SIEM to aggregate logs, ensuring they are retained long enough to accurately determine the scope of data exfiltration during a compromise.Relevant Sourceshttps://ico.org.uk/media2/njrjayzm/acro-reprimand-202608.pdfhttps://www.theregister.com/security/2026/08/12/exposed-woeful-security-at-uk-criminal-records-office-that-led-to-sensitive-data-leak/5286736
Analysis Summary
# Incident Report: ACRO Criminal Records Office Multi-Year Compromise
## Executive Summary
Between July 2021 and June 2023, the ACRO Criminal Records Office experienced three separate compromises of its customer portal due to unpatched vulnerabilities in its Kentico Content Management System (CMS). Threat actors remained active in the environment for nearly two years, staging personal data for over 10,000 subjects and successfully harvesting credentials. The incident was characterized by a significant breakdown in IT governance, specifically regarding patching accountability and security alert monitoring.
## Incident Details
- **Discovery Date:** March 2023
- **Incident Date:** 9 July 2021 – 22 June 2023
- **Affected Organization:** ACRO Criminal Records Office
- **Sector:** Law Enforcement / Public Sector
- **Geography:** United Kingdom
## Timeline of Events
### Initial Access
- **Date/Time:** 9 July 2021
- **Vector:** Exploitation of known vulnerabilities in Kentico CMS v12.0.0.
- **Details:** ACRO was running an outdated version of Kentico CMS (v12.0.0) between September 2019 and March 2023. Ambiguity regarding who was responsible for patching led to the site remaining vulnerable to multiple known exploits.
### Lateral Movement
- **Details:** While the actor maintained a long-term presence on the web environment, ACRO’s internal network segmentation effectively prevented the threat actor from pivoting from the web portal into core policing systems.
### Data Exfiltration/Impact
- **15-16 February 2023:** A threat actor staged personal data for exfiltration, including Police Certificate Applications and International Child Protection Certificate forms.
- **Scope:** A maximum of 10,920 data subjects had their data staged. On a precautionary basis, ACRO notified 84,048 individuals.
### Detection & Response
- **23 February 2023:** Trend Micro antivirus detected and quarantined four attempts to install Mimikatz. Due to a lack of alert analysis processes, these warnings were ignored.
- **March 2023:** ACRO was notified of an SQL injection attack exposing 15 sets of credentials.
- **April 2023:** ACRO began precautionary notification of data subjects.
- **7 August 2026:** The UK Information Commissioner's Office (ICO) officially disclosed the findings and issued a reprimand.
## Attack Methodology
- **Initial Access:** SQL Injection and exploitation of known CMS vulnerabilities.
- **Persistence:** Long-term environment presence (nearly 24 months).
- **Credential Access:** Attempted use of Mimikatz for credential harvesting; successful SQL injection to expose 15 credential sets.
- **Collection:** Staging of application forms (SARs, Police Certificates).
- **Exfiltration:** Likely data exfiltration (confirmed staging), though insufficient log retention prevented definitive confirmation.
- **Impact:** Compromise of sensitive personal data and potential exposure of employee credentials.
## Impact Assessment
- **Financial:** No fine issued (public sector reprimand policy), but significant forensic and migration costs.
- **Data Breach:** Exposure of credentials and staging of nearly 11,000 sensitive police-related application forms.
- **Operational:** Migration to new cloud infrastructure; temporary loss of portal services.
- **Reputational:** Public reprimand by the ICO; loss of public trust in national police unit data handling.
## Indicators of Compromise
- **Network indicators:** acro[.]police[.]uk (Compromised Portal)
- **File indicators:** Mimikatz (Credential harvesting tool)
- **Behavioral indicators:** Failed/Quarantined malware alerts ignored by staff; SQL injection activity.
## Response Actions
- **Containment:** Utilized existing network segmentation to protect core systems.
- **Eradication:** Migration of the portal from the vulnerable Kentico CMS to the Salesforce Experience Cloud.
- **Recovery:** Implementation of a Security Information and Event Management (SIEM) system to improve visibility and monitoring.
## Lessons Learned
- **Governance Failure:** Ambiguity in IT roles led to critical systems remaining unpatched for years despite known vulnerabilities.
- **Monitoring Failure:** Security tools (Trend Micro) functioned correctly but were rendered useless by the lack of a human review process for alerts.
- **Visibility Gap:** Inadequate log retention policies made it impossible to determine the full extent of data exfiltration.
## Recommendations
- **Define Patching Ownership:** Establish a clear, documented policy for who is responsible for patching public-facing assets.
- **Modernize Infrastructure:** Utilize cloud platforms (like Salesforce) that offer automated patching and managed security updates.
- **Formalize SOC Processes:** Ensure all high-priority antivirus/EDR alerts are investigated by a security analyst or a Managed Detection and Response (MDR) provider.
- **Audit Logging Policies:** Ensure logs are retained for at least 6–12 months to support forensic investigations of long-term "low and slow" attacks.