ACRO’s Portal Breaches Exposed Patch and Alert Gaps

Britain’s ACRO Criminal Records Office was censured after three intrusions between July 2021 and June 2023 exposed personal data, including records linked to domestic-violence victims. The Information Commissioner’s Office said the same public-facing customer portal kept getting hit while warnings and patch duties were left without clear ownership. The portal ran on Kentico content management system software that had stayed on the same version since September 2019, even though known vulnerabilities had fixes available. At the same time, antivirus alerts went unread, including detections tied to Mimikatz, so the warning signs sat in place while attackers kept coming back. For public-sector portals run with an MSP or supplier, the exposure does not end with a single incident if no one is clearly responsible for patching and alert review. In that setup, the same external system can stay open long enough for repeated compromise, and the evidence that should trigger containment never reaches anyone who can act on it.

Part of the PlainSec briefing for 2026-08-13

Every edition of this story: ACRO’s Portal Breaches Exposed Patch and Alert Gaps

Sources