The UK Information Commissioner’s Office reprimanded ACRO Criminal Records Office after investigators found three separate intrusions into its public-facing customer portal between 2021 and 2023, driven by long-unpatched vulnerabilities in an outdated Kentico CMS. In the most serious breach, an attacker reportedly maintained persistent access from August 2022 to March 2023, while antivirus detections and alerts — including signs of Mimikatz activity — went unread or were not acted on. The ICO said ACRO lacked clear patch-management ownership, failed to apply Kentico fixes available since 2019, and did not maintain sufficient logging to fully reconstruct attacker activity.
ACRO said network segmentation limited the compromise to the web environment, but investigators concluded that sensitive data tied to about 10,920 people may have been staged for exfiltration, including identity, financial, biometric, and criminal-record-related information. Because logging was inadequate, ACRO could not confirm whether the data was actually stolen, yet more than 84,000 people were notified as a precaution. The ICO issued a reprimand rather than a financial penalty, citing factors including ACRO’s public-sector status, and ACRO has since decommissioned the affected infrastructure, improved monitoring with a SIEM, strengthened segmentation, and migrated services to Salesforce Experience Cloud.

See attribution, scope, and your downstream exposure.
14 events from the most recent confirmed update back to the earliest known activity.
ACRO decommissioned the compromised infrastructure in June 2023, ending the period covered by the forensic investigation. The ICO clarified that this date reflected decommissioning of the affected environment, not necessarily the attackers' last access.
In April 2023, ACRO notified more than 84,000 applicants whose submissions fell within the at-risk window. Later analysis determined that data relating to no more than 10,920 individuals had potentially been staged for exfiltration.
In April 2023, ACRO publicly disclosed that it was responding to a cybersecurity incident after being contacted by the Evening Standard. At the time, ACRO said it had no evidence that data had been compromised.
On 21 March 2023, ACRO took the customer portal section of its website offline after discovering another incident in the affected environment. The compromised infrastructure continued processing limited personal data until it was fully decommissioned in June 2023.
The long-running website and CMS intrusion remained undetected until March 14, 2023, when ACRO discovered it while investigating a separate SQL injection attack. Investigators found that the SQL injection incident had exposed 15 sets of credentials, most belonging to ACRO staff.
Between February 15 and February 16, 2023, attackers staged sensitive data relating to just under 11,000 people for possible exfiltration. Investigators could not confirm whether the data was actually exfiltrated because ACRO's logging was insufficient.
The most serious intrusion began on August 5, 2022, when attackers obtained persistent access to ACRO's website and Kentico CMS. That access remained in place for more than seven months while the attackers conducted reconnaissance in the compromised environment.
Forensic investigators later found evidence of separate intrusions dating back to July 8 or 9, 2021, marking the earliest observed attacker activity in ACRO's environment. The incidents were later categorized as three distinct groups.
ACRO's managed service provider did not learn that patching Kentico was its responsibility until February 2020. Even then, it continued to assume it was not required to actively monitor for security updates.
ACRO's public-facing customer portal was running Kentico CMS version 12.0.0 from September 2019, and available security patches and hotfixes were not applied. The ICO later found ACRO lacked clear patching responsibility and documented patch-management processes for the platform.
A breach report stated that Trend Micro detected and quarantined a known threat during the ACRO incident, but ACRO did not act on the critical security alerts. The report also said the attacker reportedly used SQL injection and Mimikatz, while inadequate log retention prevented confirmation of the full extent of exfiltration.
The UK Information Commissioner's Office reprimanded ACRO over repeated security failures that enabled three separate intrusions between 2021 and 2023. The ICO said unread security alerts, poor patching, and weak logging contributed to the incidents, while network segmentation limited the compromise to the web environment.
After discovering the attack, ACRO implemented a SIEM and improved visibility, monitoring, network segmentation, and system hardening. It also migrated from the compromised environment to Salesforce Experience Cloud.
After ACRO disclosed the incident, the Medusa ransomware group claimed responsibility for the attack. However, no stolen data was published on Medusa's leak site.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyberveille.ch
Open sourcemalware.news
Open sourcedatabreaches.net
Open sourceinfosecurity-magazine.com
Open sourcetheregister.com
Open sourcetherecord.media
Open sourceico.org.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.