logo

UK: ICO reprimands ACRO Criminal Records Office after data breach

ID: fbbc8a0e-146d-5bed-a859-a46af3c1edba

STIX ID: report--fbbc8a0e-146d-5bed-a859-a46af3c1edba

Feed Name: DataBreaches.Net

Threat Score
75/100

Date Published: 2026-08-15

Date Updated: 2026-08-15

Author: Dissent

...
...

ACRO Criminal Records Office was reprimanded by the UK Information Commissioner after three compromises of its Kentico-based customer portal between July 2021 and June 2023, including an SQL injection that exposed employee credentials and a prolonged unauthorised access (Aug 2022–Mar 2023) during which personal data for up to 10,920 individuals was staged for exfiltration; insufficient logs prevented confirmation of actual data exfiltration. Affected data categories included basic identifiers, financial details, national IDs, criminal convictions, special-category data (e.g., sexual orientation, gender reassignment, disability), biometric data, and race/ethnic origin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.