An unpatched web content management system and ignored security alerts left Britain’s ACRO Criminal Records Office exposed to malicious actors for nearly two years, according to a formal reprimand notice issued by the UK Information Commissioner’s Office (ICO). Between July 2021 and June 2023, attackers compromised ACRO’s public-facing portal in three distinct security incidents, staging sensitive personal records for exfiltration and exposing police employee credentials.
The incident highlights a severe breakdown in operational governance across multi-vendor environments, where basic patching duties and security alert monitoring fell through responsibility gaps between internal teams and external suppliers.
Unheeded Warnings and Unpatched Software
The initial vector for the ACRO Criminal Records Office breach was its public customer portal, which relied on the Kentico content management system. ACRO deployed a version of Kentico in September 2019 and failed to apply any software updates or vendor security patches over the next four years. While Kentico released fixes for known vulnerabilities during this window, none were installed because ACRO, its managed service provider (MSP), and its web development vendor had no established agreement or process governing who was responsible for vulnerability management.
Compounding the unpatched CMS vulnerabilities was a complete failure in security monitoring. Throughout the attack window, ACRO’s Trend Micro security controls actively detected and quarantined malicious activity on four separate occasions, specifically stopping attempts to execute Mimikatz—a well-known post-exploitation tool used to dump plaintext passwords, Kerberos tickets, and NTLM hashes from system memory.
Despite these high-severity detections, security personnel never investigated or escalated the alerts. During the ICO’s investigation, ACRO admitted it lacked an established business process for reviewing security warnings and could not identify which roles or team members were supposed to monitor antivirus alerts.
Breakdown of the Intrusions
Forensic analysis commissioned by ACRO identified three separate intrusion events, categorized in the ICO report as Group A, Group B, and Group C:
- Group A (Persistent Web Access): The most critical intrusion saw an attacker maintain unauthorized access to the web server and Kentico CMS for seven months, from August 2022 through March 2023. After performing initial reconnaissance, the actor staged the personal records of nearly 11,000 individuals in February 2023 in preparation for exfiltration. Because ACRO failed to retain sufficient network and system logs, investigators were unable to confirm whether the staged dataset was successfully transferred off the network.
- SQL Injection Attack: Another intrusion within the multi-year window utilized SQL injection (SQLi) against the portal database. By injecting malicious SQL queries into user input fields, the threat actor bypassed application-level controls and successfully harvested internal employee credentials.
- Infrastructure Compromise: A third cluster of activity involved broader interaction with the underlying web infrastructure. The compromised environment was eventually decommissioned on June 22, 2023, bringing the window of threat actor access to a close.
Threat Actor Operations and Extortion
In April 2023, after initially claiming its portal was offline for scheduled maintenance, ACRO publicly acknowledged the incident following inquiries from journalists. Shortly thereafter, the Medusa ransomware group claimed responsibility for the intrusion on its dark web leak portal.
Medusa typically operates on a double-extortion model, exfiltrating sensitive organizational data while deploying file-encrypting ransomware across accessible endpoints. However, Medusa never published stolen ACRO records on its leak site. It remains unclear whether ACRO or a related party negotiated an undisclosed ransom payment, or if Medusa made a false claim to capitalize on public media coverage of the breach.
Operational Impact and Blast Radius
As the central police unit managing background checks, international criminal records, and Police National Computer (PNC) data requests, ACRO handles exceptionally sensitive personal information. The blast radius of the web portal compromise was substantial:
- Victim Exposure: Among the 11,000 individuals whose data was staged for exfiltration were vulnerable populations, including domestic violence victims. In total, ACRO issued precautionary notifications to over 84,000 applicants who submitted forms through the portal during the window of exposure.
- Core Systems Saved by Segmentation: A crucial technical control prevented a catastrophic compromise of broader UK law enforcement operations. ACRO’s network architecture enforced strict network segmentation between the public-facing Kentico web server and the core Police National Computer infrastructure. This boundary stopped threat actors from moving laterally from the web DMZ into primary policing databases, a key factor in the ICO’s decision to issue a reprimand rather than a financial penalty.
ACRO has since retired the affected web infrastructure, transitioned its public applications to a modernized setup, and deployed a new Security Information and Event Management (SIEM) platform to centralize log retention and alert routing.
Specific Remediation Actions
Organizations running self-hosted content management systems like Kentico or managing multi-vendor IT relationships should take immediate steps based on this incident:
- Define Patching Ownership: Audit all third-party and MSP contracts to ensure clear, written Service Level Agreements (SLAs) exist defining explicit responsibility for vendor advisory monitoring and patch application for public-facing CMS platforms.
- Audit EDR and Antivirus Alert Routing: Verify that endpoint protection suites (such as Trend Micro, Defender, or CrowdStrike) route quarantined threat detections—particularly credential-dumping utilities like Mimikatz—directly into a monitored SOC queue or automated escalation workflow rather than relying on unmonitored local console logs.
- Enforce Log Retention Policies: Configure centralized web server and application gateway logging to retain traffic and access logs for at least 12 months to ensure post-incident forensics can definitively determine data exfiltration status.
Related content
Microsoft July 2026 Patch Tuesday Addresses Critical Zero-Days and Information Leaks
Security NewsMicrosoft Fixes Actively Exploited WinSock Zero-Day in August 2026 Patch Tuesday
Security NewsAdobe Patches Maximum-Severity CVSS 10.0 Zero-Click Flaw in Campaign Classic
Security NewsCritical Adobe ColdFusion Vulnerability (CVE-2026-48282) Actively Exploited In The Wild
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call