The UK Information Commissioner’s Office has reprimanded ACRO Criminal Records Office over cyber security failings that left the personal data of up to ten thousand people exposed.

ACRO is the body that handles police certificates, international criminal record exchange, and the disclosure of UK conviction data to foreign governments. The categories of data involved reflect that: names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal offence and special category information.

That is close to the worst possible combination β€” full identity documents, financial details, biometrics, and the criminal history of people who in many cases were applying for a certificate precisely because they needed to prove they had none.

The timeline

Attackers had access to ACRO’s website and content management system for seven months, from August 2022 to March 2023. During that window they were able to stage personal information for exfiltration. ACRO could not conclusively determine whether the data was actually removed.

That inability to determine is itself a finding. It means the logging was insufficient to reconstruct what left the network β€” which, three years later, means the affected individuals still cannot be told whether their passport numbers and criminal records are in circulation.

Subsequent reporting indicates three separate intrusions went undetected across a roughly two-year period.

The cause

The ICO’s findings are not subtle:

  • ACRO did not ensure clear responsibility for identifying and monitoring critical CMS security updates. Nobody owned patching.
  • It failed to maintain an effective patch management process.
  • It did not adequately investigate security alerts that could have identified the intruder earlier.

And the detail that makes the rest redundant: the customer-facing web portal was still running the exact software version deployed in September 2019 β€” unpatched for nearly four years, across multiple publicly disclosed vulnerabilities in the intervening period.

This is not a sophisticated-adversary story. There is no zero-day, no supply-chain compromise, no clever social engineering. A public-facing web application processing criminal records and biometric data was left on a four-year-old build.

The penalty is a letter

The outcome is a reprimand. No fine.

The ICO’s public-sector approach, introduced in 2022 and extended since, deliberately favours reprimands and improvement notices over monetary penalties for government bodies. The reasoning is that fining a public body moves money from one taxpayer-funded pot to another while reducing the budget available to fix the problem, and that public naming plus mandated remediation achieves more.

There is a real argument there. There is also a real consequence: a private company with the same failure would be looking at a materially different outcome. GDPR Article 32 requires security appropriate to the risk. Four years without patching a public-facing portal holding special category criminal data is not an appropriate measure under any reading. In the private sector that produces a fine measured in millions.

The asymmetry matters because deterrence works on budgets. Patch management is unglamorous, and it competes for funding against everything else. An organisation that knows the downside is a strongly worded letter three years later prices that work accordingly.

It is also the second UK policing data governance failure to surface in short order β€” following the police database and law firm breaches earlier this year.

The specific harm to these ten thousand people

Generic breach coverage treats records as fungible. These are not.

A person whose ACRO record is exposed has lost, simultaneously: the identity documents needed to impersonate them, the bank details needed to defraud them, the biometric data that cannot be reissued, and the fact and content of their criminal record β€” including, for many, the fact that they have no convictions, which is itself sensitive because it reveals they applied for a certificate, typically for visa, employment, or immigration purposes.

Criminal record data has an unusual harm profile. Passwords can be changed and cards reissued. A conviction from 1998 is permanent, and its disclosure to an employer, landlord, or family member is not reversible by any technical control. Special category data is special precisely because the harm survives remediation.

Three years on, the affected people still do not know whether it left the building.

What it means in practice

Patch management is the whole game and it keeps not being funded. Every large breach retrospective finds a known, fixed, unapplied vulnerability. This one had four years of them.

Detection failure compounds disclosure failure. Seven months of access with insufficient logging means the organisation cannot answer the only question victims care about. Detection and forensic readiness are not luxuries layered on top of prevention; they are what determines whether a breach can be honestly disclosed.

Public-sector regulatory asymmetry has a price. Whether or not fines are the right tool, the current settlement means the organisations holding the most sensitive data in the country face the weakest financial consequence for mishandling it.

Special category data demands special engineering. Criminal records, biometrics, and health data should not sit behind a general-purpose CMS on the public internet with no patch owner.

What you can do

  1. If you have ever obtained an ACRO police certificate, assume exposure. The affected window is applications around 2022–2023, but ACRO could not determine what left. Treat your passport and driving licence numbers as compromised.

  2. Place a CIFAS Protective Registration. It costs about Β£30 for two years and forces additional identity checks on credit applications in your name. This is the correct response to exposed identity documents, and far more useful than a credit monitoring subscription.

  3. Watch for targeted phishing referencing your certificate or application. Data this specific enables convincing, personalised approaches. Legitimate bodies do not ask for bank details by email.

  4. Exercise your subject access right. You are entitled to ask ACRO what it holds about you and whether you were within the affected cohort. Reprimands rarely come with individual notification.

  5. If you run a public-facing system holding special category data, go and check the version number today. Not the ticket saying it was scheduled. The version number.