ICO Reprimands Criminal Records Office After 2023 Breach
ID: acede77c-4edc-544d-9b3c-0e74566fac8c
STIX ID: report--acede77c-4edc-544d-9b3c-0e74566fac8c
Feed Name: Infosecurity Magazine (News)
The ICO reprimanded the Criminal Records Office (ACRO) after a hacker accessed its website/CMS between August 2022 and March 2023, potentially exposing sensitive personal, financial, biometric and criminal-record data for 10,920 people. The breach was attributed to failures in patch management for the Kentico CMS and unreviewed Trend Micro alerts; ACRO has since decommissioned compromised infrastructure, migrated services, improved monitoring and network segmentation, and the ICO advised clear patching responsibilities and active alert handling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
