All incidents

UK ICO reprimands ACRO over 2023 criminal records data breach

breachopenAug 13, 2026 — Aug 15, 2026
UK ICO reprimands ACRO over 2023 criminal records data breach

THE UK Information Commissioner's Office has issued a formal reprimand to the ACRO Criminal Records Office after a data breach that exposed the personal details of up to ten thousand nine hundred and twenty individuals according to the regulator's notice.

The penalty follows an investigation into multiple incidents of unauthorised access to the ACRO customer portal that occurred between August 2022 and March 2023.

During the breach window attackers managed to stage names, financial data and criminal records for possible exfiltration.

The ICO found that insufficient logging meant investigators could not confirm whether the data actually left the network.

Coverage from databreaches.net noted that the intrusion persisted for several months and involved the staging of personal data for potential export.

Reporting by Infosecurity Magazine highlighted shortcomings in patch management and alert monitoring that contributed to the breach.

Although network segmentation helped contain the incident, the overall security arrangements did not meet the standards required by articles 32(1), 32(1)(b) and 32(1)(d).

As a result the ICO opted for a reprimand rather than a monetary penalty.

No threat actor has been publicly attributed to the activity and there is no confirmed proof that any data was misused.

Nevertheless the episode shows how blind spots in detection can weaken compliance with data-protection law.

When the compromised information includes sensitive criminal records the reputational and legal stakes are especially high.

Organisations should tighten patch cycles so that critical fixes are applied within a defined window.

Every security alert must be reviewed by a designated owner who can escalate anomalies without delay.

Logs need to capture sufficient detail to reconstruct an attacker's path and be retained long enough to support forensic work.

Regular testing of segmentation controls and frequent reviews of access rights can limit the impact of any future incident.

Incident‑response plans should be updated to address logging failures and include tabletop exercises that rehearse those scenarios.

By taking these steps firms can better satisfy the security principles of UK GDPR and reduce the chance of regulatory censure.

Intelligence briefing updated Aug 15, 2026

Root sourceico.org.uk
Timeline Coverage

Swipe to explore timeline