PrivacySignal
Breach

Three intrusions at UK criminal records office went undetected for two years

The Record · · International · Data Breaches

The UK's ACRO Criminal Records Office suffered three separate intrusions that went undetected for two years, according to a regulatory reprimand. Investigators found that antivirus alerts had gone unread and a content management system was left unpatched, leaving the agency exposed.

Why this matters: ACRO holds criminal records — some of the most sensitive personal data the government keeps on ordinary people. These are not billing details or email addresses. They are records that affect jobs, travel, and legal status. Three breaches went unnoticed for two years, not because the threat was sophisticated, but because alerts sat unread and basic software updates did not happen. That is a maintenance failure, not a mystery. The people whose records sat exposed during that time had no idea and no say.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
HIPAA Journal · · US Federal

Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation

Courts overseeing multidistrict litigation stemming from the 2024 Change Healthcare ransomware attack have established strict rules governing how the stolen dataset can be used in proceedings, reflecting the extraordinary volume and sensitivity of the compromised health information.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers

#breach#healthcare#regulation#security Read original →
Breach
The Record · · International

Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout

A ransomware group attacked a hospital system and then took over its Facebook page as part of the ongoing fallout. The attackers claim to have stolen 6 terabytes of data, including records tied to sexual assault, mental health care, abortions, and sexual harassment incidents.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
HIPAA Journal · · US Federal

Healthcare Orgs Warned About Gunra Ransomware Attacks

CISA, the FBI, and international partners have issued a joint advisory warning healthcare organizations about Gunra, a ransomware-as-a-service operation actively targeting the sector.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
BleepingComputer · · International

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla has replaced the GPG key used to cryptographically sign Firefox and Thunderbird releases after the key was accidentally exposed in a public GitHub repository. The update is intended to ensure users can continue to verify that software releases are authentic and untampered.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach Critical
BleepingComputer · · International

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →