logo

Three intrusions at UK criminal records office went undetected for two years

ID: a18f06b4-79e5-5ccd-8b43-b1f3a3851ec8

STIX ID: report--a18f06b4-79e5-5ccd-8b43-b1f3a3851ec8

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2026-08-12

Date Updated: 2026-08-12

...
...

## Executive summary The ICO reprimanded ACRO after three intrusions (July 2021–June 2023) that exploited an unpatched Kentico customer portal and ignored antivirus/security alerts; attackers staged sensitive data for nearly 11,000 people, Mimikatz-related activity was detected but not acted upon, and the Medusa ransomware group later claimed responsibility though exfiltration was unconfirmed. ACRO has decommissioned the compromised infrastructure and deployed a new SIEM, while the ICO noted network segmentation limited impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.