UK: ICO reprimands ACRO Criminal Records Office after data breach
ID: fbbc8a0e-146d-5bed-a859-a46af3c1edba
STIX ID: report--fbbc8a0e-146d-5bed-a859-a46af3c1edba
Feed Name: DataBreaches.Net
ACRO Criminal Records Office was reprimanded by the UK Information Commissioner after three compromises of its Kentico-based customer portal between July 2021 and June 2023, including an SQL injection that exposed employee credentials and a prolonged unauthorised access (Aug 2022–Mar 2023) during which personal data for up to 10,920 individuals was staged for exfiltration; insufficient logs prevented confirmation of actual data exfiltration. Affected data categories included basic identifiers, financial details, national IDs, criminal convictions, special-category data (e.g., sexual orientation, gender reassignment, disability), biometric data, and race/ethnic origin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
