databreaches.net 15 Aug 2026, 13:11 UTC

UK Watchdog Rebukes ACRO Over GDPR Breach After Data Leak

CyberSIXT Evidence Panel
Primary Source ico.org.uk

THE Information Commissioner reprimanded ACRO Criminal Records Office for violations of UK GDPR Articles 32(1), 32(1)(b), and 32(1)(d) following a cyber incident affecting up to 10,920 individuals. The breaches included multiple incidents of unauthorized access to the ACRO customer portal, notably a significant attack from August 2022 to March 2023, where personal data, including sensitive information like names, financial details, and criminal records, was staged for exfiltration. The investigation highlighted deficiencies in data logging that hindered determining if data was actually exfiltrated.

View Primary Source Via databreaches.net

Article by CyberSIXT