THE Information Commissioner reprimanded ACRO Criminal Records Office for violations of UK GDPR Articles 32(1), 32(1)(b), and 32(1)(d) following a cyber incident affecting up to 10,920 individuals. The breaches included multiple incidents of unauthorized access to the ACRO customer portal, notably a significant attack from August 2022 to March 2023, where personal data, including sensitive information like names, financial details, and criminal records, was staged for exfiltration. The investigation highlighted deficiencies in data logging that hindered determining if data was actually exfiltrated.
UK Watchdog Rebukes ACRO Over GDPR Breach After Data Leak
CyberSIXT Evidence Panel
Primary Source
ico.org.uk
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
UK Watchdog Rebukes ACRO Over GDPR Breach After Data Leak
databreaches.net
-
ICO Reprimands Criminal Records Office After 2023 Breach
cybersixt.com