Today in Surveillance:

  • The ICO reprimanded the UK criminal records office after attackers held seven months of access to its Kentico CMS. ACRO notified 84,048 people and accepted the ICO's findings. The maximum UK GDPR exposure was 17.5 million pounds; the ICO used a reprimand instead. The Register's Connor Jones reported the reprimand on August 12 [1][2].
  • The root cause was unpatched software, not a sophisticated attack. ACRO ran Kentico version 12.0.0 from September 2019 until March 2023 without applying patches or hotfixes. Trend Micro antivirus alerts generated during the intrusion went unread. The managed service provider responsible for ACRO's infrastructure did not learn that patch management was its responsibility until February 2020 [1][2].
  • Data was staged for possible exfiltration on February 15 and 16, 2023. ICO investigators determined that data relating to no more than 10,920 individuals had potentially been staged to take. The gap between that number and the 84,048 notifications reflects ACRO's determination that the larger pool was affected by the intrusion but the smaller pool was the subset the attacker appeared to be preparing to remove [1][2].
  • The data exposed is exactly the kind used to vet people for work, immigration, or travel abroad. The Register's reporting lists Police Certificate Applications, Subject Access Request forms, International Child Protection Certificate forms, names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal-offence and special-category information [1][2].
  • Jonathan Balmforth, the ICO group manager who led the action, framed it as a failure of basic cyber security. The lesson is accountability, not detection tools: organizations must have clear accountability for security updates and effective monitoring so warning signs are acted on promptly [1][2].

The ICO Reprimanded the UK Body That Handles Police Certificate Applications

The UK's Information Commissioner's Office reprimanded ACRO on August 12, 2026, The Register reported. ACRO is the criminal records office that processes Police Certificate Applications for people who need to prove their criminal record for work, immigration, or travel abroad [1][2].

The reprimand covers an intrusion investigators traced to August 5, 2022 to March 14, 2023. Investigators also found evidence of an earlier intrusion back to July 8, 2021. ACRO discovered the breach in March 2023 while investigating a separate SQL injection attack that compromised 15 sets of credentials, most belonging to ACRO staff. Data was staged for possible exfiltration on February 15 and 16, 2023, shortly before the breach was discovered. ACRO publicly disclosed the incident in April 2023 and decommissioned the compromised infrastructure in June 2023, later migrating to Salesforce Experience Cloud [1].

An ACRO spokesperson told The Register that "since the cybersecurity incident was identified in March 2023, we have worked hard to strengthen our systems and safeguards," and that the office "accepts the ICO's findings of the infringements" [1]. The full SOS vessel covers the reprimand and the ICO's published statement [2].

The Patch Gap That Let the Intruder Roam for Seven Months

The mechanism behind the reprimand is accountability, not novelty. ACRO ran Kentico version 12.0.0 from September 2019 until March 2023 without applying the patches and hotfixes the vendor released during that period [1]. Trend Micro antivirus alerts generated during the intrusion went unread; no documented handling process was in place for those alerts [1]. The managed service provider responsible for ACRO's infrastructure did not learn that patch management was its responsibility until February 2020 [1].

The ICO's finding on the accountability gap is in the reprimand itself. The Register reports the ICO as saying "the ambiguity around who was accountable for identifying necessary Kentico CMS patches created a gap where patches and hotfixes were missed, which ultimately left ACRO's website vulnerable" [1]. The same point, more broadly: "the lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology" [1].

Jonathan Balmforth, the ICO group manager who led the action, framed it as a failure of basic cyber security. His statement, as reported by The Register: "This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information." On accountability for security updates, Balmforth's statement: "Organizations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyberattacks are identified, investigated and acted upon promptly" [1]. The dual reading is the surveillance one. Detect without accountability is just a record of who failed to act. Read the UK Companies House Webfiling breach vessel and the UKGI data-leak vessel for adjacent public-records exposures.

84,048 People Were Notified. A Subset of 10,920 Was Staged for Removal.

ACRO notified 84,048 people of the breach. ICO investigators later determined that data relating to no more than 10,920 individuals had potentially been staged for exfiltration on February 15 and 16, 2023 [1]. The gap between the two numbers is not a contradiction; it is the regulator's distinction between the population affected by the intrusion and the subset the attacker appeared to be preparing to take [1].

ACRO received 35 formal complaints from affected people, citing personal distress, identity theft, and financial loss. The ICO received six [1]. The Register's reporting lists the categories of data the breach exposed: Police Certificate Applications, Subject Access Request forms, International Child Protection Certificate forms, names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal-offence and special-category information [1]. That is the dataset a state runs to issue a police certificate, vet a visa applicant, or process a Subject Access Request about a person's own police file.

The number reported is 35 complaints to ACRO from the people whose files were on the system. Six went to the ICO directly. The Register reports both figures on the same page; the staff credential count in the parallel SQL injection incident was 15, most belonging to ACRO staff [1]. The full SOS vessel tracks the count and the categories [2].

Why the ICO Used a Reprimand, Not a 17.5 Million Pound Fine

The ICO's maximum UK GDPR exposure for this kind of case is 17.5 million pounds, or 4 percent of worldwide turnover [1]. ACRO received a reprimand instead of a fine. The Register notes that reprimands are more commonly used for public-sector bodies, in part to avoid draining public funds [1].

The reprimand is on the public record, but the underlying issue is not closed. ACRO still processes the same Police Certificate Applications, Subject Access Request forms, and International Child Protection Certificate forms on the systems that handle those requests. The categories of data the breach exposed are the categories ACRO still handles. The next UK resident who needs a police certificate for an immigration application, a job abroad, or a Subject Access Request about their own police file is filling out one of these forms today.

The structural argument scales beyond ACRO. The same Kentico patching gap that hit ACRO likely affects other UK public-sector websites running the same content management system without a documented patch-management owner. The UK Cyber Action Plan vessel covers the 210 million pound programme the government is running to harden public services, and the UK surveillance-state leader vessel carries the wider arc. The Beacon CRM cyberattack vessel and the Reddit ICO fine vessel are the closest parallels in adjacent sectors [1].

What to Watch

A second ICO notice on a sister UK records body. The Kentico patching gap that hit ACRO likely affects other UK public-sector websites running the same CMS. Watch for a follow-on reprimand naming another UK records office, immigration service, or police portal with the same unpatched-CMS pattern [1].

Whether ACRO publishes its current patch-management policy. The ICO's reprimand explicitly called out missing oversight arrangements. If ACRO publishes the policy that closed the gap, that document is the benchmark other UK public-sector bodies will be measured against when the next regulator visits [1].

Whether ACRO migrates the Subject Access Request workflow off the same infrastructure. SAR forms were among the categories exposed. SARs are also the workflow used by people exercising their UK GDPR right of access. A new SAR portal under the Salesforce Experience Cloud stack is the test of whether the migration is paper-only or actual [1].

Whether the October 2025 ICO guidance on patch management is treated as enforceable. The reprimand's underlying message, that organizations must have clear accountability for identifying, assessing, and applying security updates, reads like a test case for prior guidance. Other UK public-sector bodies watching the ACRO file will draw conclusions from any enforcement that follows [1].

The continuing BTP London Underground live facial recognition trial from yesterday's briefing. The trial launched on August 11 at Victoria station and runs for four months across additional Underground concourses. The next signal is the next station list and the start-of-trial perception research readout [3].

Sources

  1. The Register, Connor Jones: Exposed: Woeful security at UK criminal records office that led to sensitive data leak, August 12, 2026. https://www.theregister.com/security/2026/08/12/exposed-woeful-security-at-uk-criminal-records-office-that-led-to-sensitive-data-leak/5286736
  2. State of Surveillance: Attackers Spent Seven Months Inside the UK Criminal Records Office, the day's vessel on the ICO reprimand. /news/uk-acro-criminal-records-office-ico-reprimand-kentico-breach-2026
  3. State of Surveillance: Daily Surveillance Briefing, August 12, 2026, the prior briefing covering BTP London Underground live facial recognition, CATANA SIM attacks, Signal Automatic Key Verification, Mozilla Firefox signing key, Spain deepfake, and the EFF amicus brief. /news/daily-surveillance-briefing-august-12-2026