ACRO, the criminal records processor used by all 43 police forces, left its website unpatched for three and a half years. Antivirus caught the hackers four times; nobody read the alerts, and a reprimand was still ruled enough.
Estimated reading time: 6 minutes
In short. The Information Commissioner reprimanded ACRO Criminal Records Office on 7 August 2026 for infringing Articles 32(1), 32(1)(b) and 32(1)(d) UK GDPR [2], after threat actors exploited an unpatched website between July 2021 and June 2023, staging for exfiltration data on up to 10,920 people, including criminal convictions, domestic-violence-victim status and biometric data (pages 6, 18) [1]. The notice's own findings record antivirus software that caught the intruders installing a known credential-harvesting tool four times in a single day without anyone reviewing the alert (page 14), and states plainly that investigating those alerts "would likely" have prevented further damage (page 15) [1]. The Commissioner's conclusion is still that a reprimand alone is "an effective, proportionate and dissuasive measure" (page 18) [1]. Four documented mistakes: three stars.
ACRO Criminal Records Office is not a household name, but it sits behind one most people have heard of: the Disclosure and Barring Service process, Police Certificates for visas and jobs abroad, International Child Protection Certificates, and the processing of Subject Access Requests on behalf of every force in England and Wales. It operates under a Police Act 1996 collaboration agreement signed by all 43 forces, which are its joint data controllers, with the National Police Chiefs' Council chairing its governance board [1]. Between 9 July 2021 and 22 June 2023, a threat actor had three separate periods of unauthorised access to the Kentico content management system running ACRO's customer-facing website (page 5) [1].
What was exposed
The most serious of the three, referred to throughout the notice as "Group A", ran from 5 August 2022 to 14 March 2023; between 15 and 16 February 2023 the attacker staged data for exfiltration from Police Certificate applications, Subject Access Request forms and International Child Protection Certificate forms (page 5) [1]. ACRO's own logs were not good enough to say for certain whether that staged data actually left the network (page 5) [1]. Up to 10,920 people had personal data potentially staged, drawn from categories that include criminal convictions, "persons who are the perpetrator of domestic violence", people "subject to domestic violence", biometric data, and financial account details (page 6) [1]. ACRO went on to notify 84,048 people on a precautionary basis, everyone who had applied between 17 January and 21 March 2023 (page 7) [1]. Thirty-five of those people complained directly to ACRO, reporting distress and fears of identity theft and financial loss, including people connected to Police Certificates, International Child Protection Certificates and domestic violence cases (page 7) [1].
The claim and the evidence
The notice's own account of why this happened is unusually specific, because the Commissioner's investigators were able to establish exactly what ACRO's existing security tools saw and did nothing about. ACRO's infrastructure ran Trend Micro antivirus software throughout the period, and the record shows it worked: it "did successfully detect and quarantine several threat actor tools during the incidents" (page 13) [1]. On 23 February 2023, Trend Micro detected and quarantined four separate attempts to install Mimikatz, a widely known credential-harvesting tool, on a server that ACRO's managed service provider was separately required to reboot that same month (page 14) [1]. None of those four alerts was investigated or acted on by anyone, at ACRO or any of its contracted suppliers (page 15) [1]. The Commissioner's own assessment of what that failure cost is direct: "Had the alerts been investigated by ACRO at the time, and an appropriate response conducted, it is likely that further malicious activity could have been prevented" (page 14) [1].
The alerts went unread partly because nobody at ACRO could tell the Commissioner's investigators who was supposed to be reading them. ACRO "could not establish which roles previously held responsibility for monitoring security alerts" during the period the attacker was active (page 15) [1]. The same gap existed one level up, in patching. ACRO's website ran Kentico CMS version 12.0.0 from September 2019 to March 2023, a version with known vulnerabilities, and the vendor released cumulative security hotfixes across that entire window, September 2019 to July 2023, none of which were applied (page 10) [1]. A February 2020 email exchange confirmed that ACRO's web development supplier was responsible for applying Kentico patches, but the notice records that it "did not establish whether [the supplier] was obligated to actively monitor for these", and ACRO itself did not monitor for required patches either (pages 9, 11) [1]. Three and a half years of missed patches, and nobody's job description covered noticing they were missing.
The gap before the reprimand
The Commissioner treated the breach as ending on 22 June 2023, when the compromised infrastructure was fully decommissioned (page 6) [1]. The Notice of Intent that precedes a reprimand was not served on ACRO until 10 June 2026, almost three years later; ACRO's written representations followed on 1 July 2026, and the reprimand itself is dated 7 August 2026 (page 3) [1]. The notice gives no explanation for the length of that gap.
The claims, tested
| The Commissioner's own words | What the record shows | Verdict |
|---|---|---|
| A reprimand is "an effective, proportionate and dissuasive measure" (page 18) [1] | The same notice finds that investigating ignored antivirus alerts "would likely" have prevented further malicious activity (page 14) [1] | A no-penalty outcome for a breach the regulator's own evidence calls avoidable |
| ACRO had "appropriate technical and organisational measures" obligations under Article 32(1)(b) | Kentico CMS ran unpatched from September 2019 to March 2023 despite vendor hotfixes released throughout (page 10) [1] | Three and a half years of known, unapplied fixes |
| Security responsibilities were contracted out to named suppliers | Nobody, ACRO or supplier, could tell investigators who owned patch monitoring or alert review (pages 11, 15) [1] | An accountability gap at both the patching and detection stage |
| The breach was investigated and resolved through the Commissioner's standard process | Infrastructure decommissioned 22 June 2023; Notice of Intent not served until 10 June 2026 (page 3) [1] | Almost three years between the breach ending and formal action starting, unexplained |
Credit where due
ACRO commissioned its own forensic investigation once alerted by Hampshire and Isle of Wight Constabulary's Joint ICT department, and the notice records genuine remedial work since: decommissioning the compromised infrastructure, migrating to Salesforce Experience Cloud (where patching now sits inside a vendor change-management process), implementing a SIEM platform, and strengthening network segmentation (page 8) [1]. The Commissioner explicitly "welcomes" those steps in reaching the reprimand decision, and the notice is candid about where ACRO's evidence ran out, rather than papering over the gaps [1].
Verdict
Three stars, from four documented mistakes. None of this disputes that ACRO was the victim of a criminal attack, or that its remedial work since is real. What the notice's own text does not support is its closing claim that a reprimand, alone, answers a breach its own investigators say was probably preventable, by an organisation that processes criminal-record and domestic-violence data for every police force in the country, and that took almost three years to even reach a Notice of Intent.
The star score counts four documented mistakes: a "reprimand alone is sufficient" conclusion set against the notice's own finding that investigating ignored antivirus alerts would likely have prevented further damage; a Kentico CMS left unpatched for three and a half years despite continuous vendor hotfixes; an accountability gap where nobody, ACRO or its contracted suppliers, could say who owned patch monitoring or alert review; and an unexplained near-three-year gap between the breach ending and the Notice of Intent that starts the Commissioner's formal process. Four falls in the 4 to 9 band: three stars; the bands are on the ratings page. This piece makes no finding against the accuracy of the breach timeline or technical detail the Commissioner establishes, which is detailed and, on its own terms, convincing; the finding is narrower, that the regulator's own stated justification for stopping at a reprimand does not fully hold up against its own evidence of a preventable, years-long failure. Checked directly against the 18-page reprimand PDF (full text) and the ICO enforcement page, both fetched 4 October 2026.
Sources
- Reprimand: ACRO Criminal Records Office (PDF), Information Commissioner's Office, dated 7 August 2026
- ACRO Criminal Records Office, Information Commissioner's Office enforcement action page, 7 August 2026