ACRO Criminal Records Office · cyber security

The cyberattack everyone detected and nobody saw.

Britain's criminal-records office had a working sensor. It lacked the accountable handoff that could turn an alert into action.

Between July 2021 and June 2023, forensic investigators found three compromises of ACRO's public-facing website and Kentico content-management system. On one day, Trend Micro quarantined four attempts to install Mimikatz, a credential-dumping tool. The alerts were not investigated or escalated.

Primary finding: Information Commissioner's Office reprimand, published 12 August 2026.

Two signal paths reach a missing relay A warm red attacker path and a cool blue defence path meet at a broken relay labelled alert to action. The missing relay is marked no owner found. LIVE TRACE / FEB 2023 ATTACKER PATH DEFENCE PATH ACCESS PERSISTENCE STAGING DETECT QUARANTINE ×4 SEGMENT ALERT TO ACTION NO OWNER FOUND RECON CREDENTIALS LOGS THIN BOUNDARY HOLDS
attacker activity defensive signal missing institutional handoff
3separate compromises
7months of access in Group A
10,920people's data staged for exfiltration
Mimikatz attempts quarantined in one day
Follow the handoff

The finding

The machine raised its hand. The organisation did not.

ACRO handles police certificates, subject access requests and international child protection certificates for the 43 participating police forces. Its public web environment held information that can identify applicants, people with criminal records, victims and perpetrators of domestic violence.

The ICO's forensic account separates five controls that are often flattened into one word, “security”. Patching failed. Detection worked. Alert interpretation failed. Logs were inadequate. Network segmentation held.

The evidence chain

Two stories ran on the same clock.

Read the same dates through either rail. The switch changes emphasis, not the underlying evidence.

Attacker's path is in focus.

what the attacker was doing what ACRO's defences were seeing where the handoff failed
Date What the attacker was doing What ACRO's defences were seeing
  1. entry condition

    The initial exploit was never pinned down.

    The ICO assessed an unpatched Kentico vulnerability as the highly likely route in.

    patch signal

    Kentico stayed on version 12.0.0.

    Cumulative security hotfixes were released. None were applied. Ownership for monitoring releases was unclear.

  2. Group C

    Activity appears on the public site and CMS.

    The ICO's forensic investigation places attacker activity here, almost two years before the decision was published.

    visibility gap

    The event did not become an incident.

    The public record does not identify an alert-to-action chain for this compromise.

  3. Group A

    Persistent access begins.

    The principal intrusion kept unauthorised access from 5 August 2022 until 14 March 2023.

    monitoring gap

    Seven months pass inside the web environment.

    The later finding identifies the duration. It does not identify a functioning owner for escalation.

  4. staging

    Data from up to 10,920 people is prepared for exfiltration.

    Police Certificate, Subject Access Request and International Child Protection Certificate material was assembled.

    forensics

    The trail is too thin to answer the last question.

    ACRO did not retain enough logs to establish whether the staged files left the network.

  5. credential theft

    Four Mimikatz installation attempts arrive.

    Mimikatz is a well-known tool for extracting credentials. The attacker tried four times in one day.

    signal received

    Trend Micro quarantines all four attempts.

    Alerts were generated. Nobody ACRO could identify was assigned to read and escalate them.

  6. access ends

    Group A's seven-month foothold closes.

    The forensic window for the principal intrusion ends.

    response absent

    The likely preventable window is gone.

    The ICO says investigation and appropriate response to the historical alerts would likely have prevented further malicious activity.

  7. public incident

    The website is finally taken offline.

    ACRO first described the outage publicly as website maintenance, before acknowledging a cyber security incident.

    containment

    Segmentation keeps the attacker at the web boundary.

    The ICO says the attacker could not move from the compromised web environment into core policing systems.

  8. Group B / C

    The public evidence window ends.

    The ICO records attacker activity across three compromises through this date.

    evidence limit

    The record is still incomplete.

    The published material does not identify whether the groups were one actor or several.

Dates compress the chronology disclosed in the ICO's reprimand. The labels Group A, Group B and Group C are the regulator's labels. They are not public attribution.

The missing relay

The sensors worked. The institutional circuit stopped.

The intelligence cycle broke at the point where an observation should become a decision.

  1. 01 Collection Malicious tools detected

    Trend Micro saw and quarantined attacker tools.

  2. 02 Processing Alerts generated

    The defensive software recorded a signal.

  3. 03 Dissemination Reader unassigned

    ACRO could not establish who was meant to review and escalate alerts.

  4. 04 Decision Incident response never starts

    The regulator says further malicious activity was likely preventable.

  5. 05 Containment Boundary holds

    Network segmentation prevents movement into core policing systems.

The reusable lesson

A warning system can work perfectly and the organisation can still receive no warning when nobody owns the act of noticing.

10,920 people's data staged for exfiltration

What was in the files

The records were sensitive because the people were.

The staged material came from Police Certificate applications, Subject Access Requests and International Child Protection Certificate applications. It could include identity and travel documents, addresses, bank details, biometric information, criminal-offence data, protected characteristics, and information identifying victims and perpetrators of domestic violence.

identitypassport and driving licenceNational Insurancebank accountbiometriccriminal offencerace and ethnicitydomestic violence

Evidence limit. The ICO establishes staging, which is preparation for exfiltration. Insufficient retained logs mean it cannot establish whether those files actually left the network.

Control failure

Four questions the supplier chain could not answer.

Each box is a different job. Combining them under the word “maintenance” leaves the security function without a clear owner.

  1. Unowned

    PATCH AVAILABLE

    Who monitors the vendor's fixes?

    Kentico released cumulative security hotfixes. Nobody was clearly responsible for noticing that they needed applying.

  2. Unowned

    MALWARE DETECTED

    Who reads the alert?

    Trend Micro quarantined tools and generated alerts. ACRO could not identify the role or process meant to escalate them.

  3. Insufficient

    DATA STAGED

    Did it leave?

    The answer remains unknown because logs were not retained at the level needed to reconstruct exfiltration.

  4. Worked

    MOVE DEEPER

    Could the attacker cross the boundary?

    Network segmentation prevented movement from the compromised web environment into core policing systems.

What the record can support

The strong conclusion is organisational.

The forensic evidence is strong on persistence, staging and control failures. It is deliberately weaker on removal and attribution.

Documented
  • Three compromises of the public-facing website and Kentico CMS.
  • Unauthorised Group A access from 5 August 2022 to 14 March 2023.
  • Up to 10,920 people's data staged for exfiltration.
  • Four Mimikatz installation attempts quarantined on 23 February 2023.
  • Network segmentation blocked movement into core policing systems.
Still open
  • Whether the staged files actually left ACRO's network.
  • Whether Groups A, B and C were one operator or several.
  • Who the operators were, including whether a state service was involved.
  • Whether the later Medusa claim was genuine. No stolen ACRO data was published.

The ICO does not attribute the breach to Medusa. There is no public evidence in the supplied record of a state intelligence service behind the intrusions.

Relevanță pentru România

Întrebarea care trebuie să apară în contract.

În cazul ACRO, responsabilitatea a fost împărțită între instituție și furnizorii săi. Problema nu a fost lipsa totală a tehnologiei. A lipsit un proprietar clar pentru fiecare pas: aflarea vulnerabilității, citirea alertei și declararea incidentului.

„Cine este obligat contractual să afle că a apărut vulnerabilitatea, cine trebuie să citească alerta și cine trebuie să decidă că e incident?”
Aflăvulnerabilitatea Citeștealerta Decidecă e incident

The disclosed ACRO breach has no direct Romanian connection. The procurement question is transferable because public systems often split responsibility across an institution, an infrastructure provider, a software contractor and security vendors.

Evidence and limits

Read the record, then mark the edge of it.

The primary source is the ICO's completed investigation. Secondary sources provide chronology and the public contrast with what was known in April 2023.

  1. Primary record · 18 pages

    Information Commissioner's Office, “ACRO reprimanded following cyber security failings”

    Published 12 August 2026. The underlying decision is dated 7 August 2026. The reprimand documents the three compromises, persistent access, staged data, unpatched Kentico CMS, antivirus detections, alert-handling gaps, inadequate logs and successful segmentation.

    Read the ICO finding
  2. Independent chronology · 12 August 2026

    The Record from Recorded Future News, “Three intrusions at UK criminal records office went undetected for two years”

    The Record examined the notice and reports the unresolved question of whether the three groups were one actor or several. It does not turn the later Medusa claim into attribution.

    Read the independent account
  3. Contemporaneous government answer · 24 April 2023

    UK Parliament, written question 181663, “Police National Computer: Cybersecurity”

    The Home Office said ACRO had no conclusive evidence at that time that personal data had been affected. The later ICO finding makes the distinction between staging and confirmed exfiltration essential.

    Read the parliamentary answer
  4. Earlier public account · 6 April 2023

    The Record, “UK criminal records office admits ‘website maintenance’ was cyber incident”

    The contemporaneous report records the initial public description of the outage and ACRO's later acknowledgement that the customer portal had been taken offline after the incident was known.

    Read the earlier account

The question that remains

Who was meant to notice?

For months, ACRO's machines recorded traces of an attacker. The missing control was a person or team with the authority and duty to turn those traces into a response.

Return to the evidence