Three intrusions at UK criminal records office went undetected for two years
ID: a18f06b4-79e5-5ccd-8b43-b1f3a3851ec8
STIX ID: report--a18f06b4-79e5-5ccd-8b43-b1f3a3851ec8
Feed Name: The Record from Recorded Future News
## Executive summary The ICO reprimanded ACRO after three intrusions (July 2021–June 2023) that exploited an unpatched Kentico customer portal and ignored antivirus/security alerts; attackers staged sensitive data for nearly 11,000 people, Mimikatz-related activity was detected but not acted upon, and the Medusa ransomware group later claimed responsibility though exfiltration was unconfirmed. ACRO has decommissioned the compromised infrastructure and deployed a new SIEM, while the ICO noted network segmentation limited impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
