Three intrusions at UK criminal records office went undetected for two years
The UK's ACRO Criminal Records Office suffered three separate intrusions that went undetected for two years, according to a regulatory reprimand. Investigators found that antivirus alerts had gone unread and a content management system was left unpatched, leaving the agency exposed.
Why this matters: ACRO holds criminal records — some of the most sensitive personal data the government keeps on ordinary people. These are not billing details or email addresses. They are records that affect jobs, travel, and legal status. Three breaches went unnoticed for two years, not because the threat was sophisticated, but because alerts sat unread and basic software updates did not happen. That is a maintenance failure, not a mystery. The people whose records sat exposed during that time had no idea and no say.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.