Brian Sims
Editor
Brian Sims
Editor
THE INFORMATION Commissioner’s Office (ICO) has reprimanded the ACRO Criminal Records Office (ACRO) after cyber security failings left the personal information of up to ten thousand people – including some individuals’ sensitive data – potentially exposed.
The ICO’s investigation found that, between August 2022 and March 2023, a hacker gained unauthorised access to ACRO’s website and content management system (CMS). The attacker was able to stage personal information to be stolen, although ACRO could not conclusively determine whether the information was removed from its systems.
The investigation found that up to 10,920 individuals may have been affected. The data potentially exposed included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data and highly sensitive criminal offence and special category information.
Those affected included applicants for Police Certificates and International Child Protection Certificates, subject access request applicants and third parties connected to those applications.
Significant risks
Jonathan Balmforth, the ICO’s Group manager for civil and cyber investigations, commented: “This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly so where organisations process large volumes of highly sensitive personal information.”
Balmforth continued: “Organisations must ensure there’s clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyber attacks are identified, investigated and acted upon on a prompt basis.”
Further, Balmforth noted: “The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology.”
In conclusion, Balmforth said: “We welcome the improvements ACRO has made since these incidents. We hope other organisations will use this case as an opportunity to review their own processes and responses to ensure personal information remains properly protected.”
Investigation findings
The ICO found that ACRO had engaged third party providers to deliver certain security services, including patch management. However, ACRO didn’t ensure clear responsibility for identifying and monitoring critical CMS security updates, failed to maintain an effective patch management process and didn’t adequately investigate security alerts that could have identified the hacker’s activity at an earlier point in time.
In deciding to issue a reprimand, the ICO took into account a number of mitigating factors. Network segmentation prevented the hacker from moving beyond the compromised website environment into core systems, in turn reducing the potential scale of harm.
The ICO additionally welcomed the remedial action taken by ACRO following the incident, including decommissioning the compromised infrastructure, migrating services elsewhere, implementing security monitoring, improving visibility of cyber threats and strengthening network segmentation.
*Further information is available online at www.ico.org.uk
Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM
01342 31 4300