TL;DR: The UK's Information Commissioner's Office reprimanded ACRO, the criminal records office, on August 12, 2026 after attackers held seven months of access to its website. ACRO ran Kentico CMS version 12.0.0 from September 2019 until March 2023 without applying patches. The office notified 84,048 people and acknowledged the ICO's findings. No fine was issued.
What Happened at ACRO
ACRO is the UK body that processes Police Certificate Applications for people who need to prove their criminal record for work, immigration, or travel abroad. The Register's Connor Jones reported on August 12 that the ICO reprimanded ACRO after an intruder held persistent access to ACRO's website and Kentico content management system from August 5, 2022 to March 14, 2023 [1].
The intrusion was the most serious of several. Investigators traced earlier intrusion evidence back to July 8, 2021. Data was staged for possible exfiltration on February 15 and 16, 2023. ACRO discovered the breach in March 2023 while investigating a separate SQL injection attack that compromised 15 sets of credentials, most belonging to ACRO staff [1]. ACRO publicly disclosed the breach in April 2023 and decommissioned the compromised infrastructure in June 2023, later migrating to Salesforce Experience Cloud [1].
The data ACRO held is the kind of information that lets a state issue police certificates, run background checks, and vet people for work or immigration. The Register's reporting lists Police Certificate Applications, Subject Access Request forms, International Child Protection Certificate forms, names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal-offence and special-category information [1].
The CMS Gap That Let It Happen
The root cause was unpatched software. ACRO ran Kentico version 12.0.0 from September 2019 until March 2023 without applying the patches and hotfixes the vendor released during that period [1]. Trend Micro antivirus alerts generated during the intrusion went unread [1]. The managed service provider responsible for ACRO's infrastructure did not learn that patch management was its responsibility until February 2020 [1].
The ICO's finding on the accountability gap is in the reprimand itself. The Register reports the ICO as saying "the ambiguity around who was accountable for identifying necessary Kentico CMS patches created a gap where patches and hotfixes were missed, which ultimately left ACRO's website vulnerable" [1]. The same point, more broadly: "the lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology" [1].
Jonathan Balmforth, the ICO group manager who led the action, framed it as a failure of basic cyber security, not exotic tradecraft: "This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information" [1].
The Numbers ACRO Reported
ACRO notified 84,048 people of the breach. ICO investigators later determined that data relating to no more than 10,920 individuals had potentially been staged for exfiltration [1]. The gap between the two numbers reflects the ICO's determination that the larger pool was affected by the intrusion but the smaller pool was the subset the attacker appeared to be preparing to take [1]. ACRO received 35 formal complaints from affected people. The ICO received six [1].
An ACRO spokesperson told The Register that "since the cybersecurity incident was identified in March 2023, we have worked hard to strengthen our systems and safeguards," and that the office "accepts the ICO's findings of the infringements" [1].
Why the ICO Used a Reprimand, Not a Fine
The ICO's maximum UK GDPR exposure for this kind of case is £17.5 million, or 4 percent of worldwide turnover [1]. ACRO received a reprimand instead of a fine. The Register notes that reprimands are more commonly used for public sector bodies, in part to avoid draining public funds [1].
The reprimand is on the public record, but the underlying issue is not closed. ACRO still holds Police Certificate Applications, Subject Access Request forms, and International Child Protection Certificate forms on the systems that process those requests. The breach exposed exactly those categories of data [1]. The next UK resident who needs a police certificate for an immigration application, a job abroad, or a Subject Access Request about their own police file is filling out one of these forms today.
What to Watch
A second ICO notice on a sister UK records body. The same Kentico patching gap that hit ACRO likely affects other UK public-sector websites running the same CMS. Watch for a follow-on reprimand naming another UK records office, immigration service, or police portal with the same unpatched-CMS pattern [1].
Whether ACRO publishes its current patch-management policy. The ICO's reprimand explicitly called out missing oversight arrangements. If ACRO publishes the policy that closed the gap, that document is the benchmark other UK public-sector bodies will be measured against when the next regulator visits [1].
Whether ACRO migrates the Subject Access Request workflow off the same infrastructure. The SAR forms were among the categories of data exposed. SARs are also the workflow used by people exercising their UK GDPR right of access. A new SAR portal under the Salesforce Experience Cloud stack is the test of whether the migration is paper-only or actual [1].
Sources
- The Register: "Exposed: Woeful security at UK criminal records office that led to sensitive data leak" by Connor Jones (August 12, 2026)
- State of Surveillance: UK Companies House Webfiling Breach: 5 Million Directors (prior UK public-records breach coverage)
- State of Surveillance: UKGI Data Leak Exposes 51 Government Officials (prior UK central-government data exposure coverage)
- State of Surveillance: Reddit Fined £14.5M in UK Over Children's Privacy (prior ICO enforcement on age-appropriate design code)
- State of Surveillance: Beacon CRM Cyberattack Hits UK Charity Donor Records (prior UK third-party CRM breach coverage)