TEARDOWN Published 4 October 2026 at 04:52. Evidence-based. Source-cited. No sponsored content.

ACRO, the criminal records processor used by all 43 police forces, left its website unpatched for three and a half years. Antivirus caught the hackers four times; nobody read the alerts, and a reprimand was still ruled enough.

3 out of 5 stars3/54 documented mistakes in this teardownHow ratings work

Estimated reading time: 6 minutes

Hampshire Constabulary's Operational Headquarters, a red-brick building on a street corner in Winchester, with police signage and a wall-mounted banner at street level.
Hampshire and Isle of Wight Constabulary's Operational Headquarters, Winchester, photographed 31 July 2020. ACRO Criminal Records Office is hosted by Hampshire and Isle of Wight Constabulary's Joint ICT department. Photo: Barry Shimmon / Wikimedia Commons, CC BY-SA 2.0.

In short. The Information Commissioner reprimanded ACRO Criminal Records Office on 7 August 2026 for infringing Articles 32(1), 32(1)(b) and 32(1)(d) UK GDPR [2], after threat actors exploited an unpatched website between July 2021 and June 2023, staging for exfiltration data on up to 10,920 people, including criminal convictions, domestic-violence-victim status and biometric data (pages 6, 18) [1]. The notice's own findings record antivirus software that caught the intruders installing a known credential-harvesting tool four times in a single day without anyone reviewing the alert (page 14), and states plainly that investigating those alerts "would likely" have prevented further damage (page 15) [1]. The Commissioner's conclusion is still that a reprimand alone is "an effective, proportionate and dissuasive measure" (page 18) [1]. Four documented mistakes: three stars.

ACRO Criminal Records Office is not a household name, but it sits behind one most people have heard of: the Disclosure and Barring Service process, Police Certificates for visas and jobs abroad, International Child Protection Certificates, and the processing of Subject Access Requests on behalf of every force in England and Wales. It operates under a Police Act 1996 collaboration agreement signed by all 43 forces, which are its joint data controllers, with the National Police Chiefs' Council chairing its governance board [1]. Between 9 July 2021 and 22 June 2023, a threat actor had three separate periods of unauthorised access to the Kentico content management system running ACRO's customer-facing website (page 5) [1].

What was exposed

The most serious of the three, referred to throughout the notice as "Group A", ran from 5 August 2022 to 14 March 2023; between 15 and 16 February 2023 the attacker staged data for exfiltration from Police Certificate applications, Subject Access Request forms and International Child Protection Certificate forms (page 5) [1]. ACRO's own logs were not good enough to say for certain whether that staged data actually left the network (page 5) [1]. Up to 10,920 people had personal data potentially staged, drawn from categories that include criminal convictions, "persons who are the perpetrator of domestic violence", people "subject to domestic violence", biometric data, and financial account details (page 6) [1]. ACRO went on to notify 84,048 people on a precautionary basis, everyone who had applied between 17 January and 21 March 2023 (page 7) [1]. Thirty-five of those people complained directly to ACRO, reporting distress and fears of identity theft and financial loss, including people connected to Police Certificates, International Child Protection Certificates and domestic violence cases (page 7) [1].

The claim and the evidence

The notice's own account of why this happened is unusually specific, because the Commissioner's investigators were able to establish exactly what ACRO's existing security tools saw and did nothing about. ACRO's infrastructure ran Trend Micro antivirus software throughout the period, and the record shows it worked: it "did successfully detect and quarantine several threat actor tools during the incidents" (page 13) [1]. On 23 February 2023, Trend Micro detected and quarantined four separate attempts to install Mimikatz, a widely known credential-harvesting tool, on a server that ACRO's managed service provider was separately required to reboot that same month (page 14) [1]. None of those four alerts was investigated or acted on by anyone, at ACRO or any of its contracted suppliers (page 15) [1]. The Commissioner's own assessment of what that failure cost is direct: "Had the alerts been investigated by ACRO at the time, and an appropriate response conducted, it is likely that further malicious activity could have been prevented" (page 14) [1].

The alerts went unread partly because nobody at ACRO could tell the Commissioner's investigators who was supposed to be reading them. ACRO "could not establish which roles previously held responsibility for monitoring security alerts" during the period the attacker was active (page 15) [1]. The same gap existed one level up, in patching. ACRO's website ran Kentico CMS version 12.0.0 from September 2019 to March 2023, a version with known vulnerabilities, and the vendor released cumulative security hotfixes across that entire window, September 2019 to July 2023, none of which were applied (page 10) [1]. A February 2020 email exchange confirmed that ACRO's web development supplier was responsible for applying Kentico patches, but the notice records that it "did not establish whether [the supplier] was obligated to actively monitor for these", and ACRO itself did not monitor for required patches either (pages 9, 11) [1]. Three and a half years of missed patches, and nobody's job description covered noticing they were missing.

The gap before the reprimand

The Commissioner treated the breach as ending on 22 June 2023, when the compromised infrastructure was fully decommissioned (page 6) [1]. The Notice of Intent that precedes a reprimand was not served on ACRO until 10 June 2026, almost three years later; ACRO's written representations followed on 1 July 2026, and the reprimand itself is dated 7 August 2026 (page 3) [1]. The notice gives no explanation for the length of that gap.

The claims, tested

The Commissioner's own words What the record shows Verdict
A reprimand is "an effective, proportionate and dissuasive measure" (page 18) [1] The same notice finds that investigating ignored antivirus alerts "would likely" have prevented further malicious activity (page 14) [1] A no-penalty outcome for a breach the regulator's own evidence calls avoidable
ACRO had "appropriate technical and organisational measures" obligations under Article 32(1)(b) Kentico CMS ran unpatched from September 2019 to March 2023 despite vendor hotfixes released throughout (page 10) [1] Three and a half years of known, unapplied fixes
Security responsibilities were contracted out to named suppliers Nobody, ACRO or supplier, could tell investigators who owned patch monitoring or alert review (pages 11, 15) [1] An accountability gap at both the patching and detection stage
The breach was investigated and resolved through the Commissioner's standard process Infrastructure decommissioned 22 June 2023; Notice of Intent not served until 10 June 2026 (page 3) [1] Almost three years between the breach ending and formal action starting, unexplained

Credit where due

ACRO commissioned its own forensic investigation once alerted by Hampshire and Isle of Wight Constabulary's Joint ICT department, and the notice records genuine remedial work since: decommissioning the compromised infrastructure, migrating to Salesforce Experience Cloud (where patching now sits inside a vendor change-management process), implementing a SIEM platform, and strengthening network segmentation (page 8) [1]. The Commissioner explicitly "welcomes" those steps in reaching the reprimand decision, and the notice is candid about where ACRO's evidence ran out, rather than papering over the gaps [1].

Verdict

Three stars, from four documented mistakes. None of this disputes that ACRO was the victim of a criminal attack, or that its remedial work since is real. What the notice's own text does not support is its closing claim that a reprimand, alone, answers a breach its own investigators say was probably preventable, by an organisation that processes criminal-record and domestic-violence data for every police force in the country, and that took almost three years to even reach a Notice of Intent.

The star score counts four documented mistakes: a "reprimand alone is sufficient" conclusion set against the notice's own finding that investigating ignored antivirus alerts would likely have prevented further damage; a Kentico CMS left unpatched for three and a half years despite continuous vendor hotfixes; an accountability gap where nobody, ACRO or its contracted suppliers, could say who owned patch monitoring or alert review; and an unexplained near-three-year gap between the breach ending and the Notice of Intent that starts the Commissioner's formal process. Four falls in the 4 to 9 band: three stars; the bands are on the ratings page. This piece makes no finding against the accuracy of the breach timeline or technical detail the Commissioner establishes, which is detailed and, on its own terms, convincing; the finding is narrower, that the regulator's own stated justification for stopping at a reprimand does not fully hold up against its own evidence of a preventable, years-long failure. Checked directly against the 18-page reprimand PDF (full text) and the ICO enforcement page, both fetched 4 October 2026.

Sources

  1. Reprimand: ACRO Criminal Records Office (PDF), Information Commissioner's Office, dated 7 August 2026
  2. ACRO Criminal Records Office, Information Commissioner's Office enforcement action page, 7 August 2026
SHARE THIS ARTICLEXBlueskyMastodonLinkedInRedditEmail