2026 ACRO Criminal Records Office — ICO reprimand; up to 10,920 subjects (portal/CMS 2021–2023)
Data compromised
Up to 10,920 data subjects with staged Police Certificate / SAR / International Child Protection Certificate data: identifiers, DOB, address proofs, NI/DL/passport, financial account/sort codes, criminal convictions/offences, domestic-violence related data, disability/gender-reassignment/sexual-orientation, biometrics, race/ethnicity (elements varied). Exfiltration not definitively proven due to insufficient logs.
Technical writeup
Regulator-attested historical portal breaches — August 15, 2026 ICO reprimand. ACRO’s customer portal (acro.police.uk, then Kentico CMS) suffered three compromise periods between July 2021 and June 2023. The most significant (“Group A”) involved unauthorized CMS access 5 Aug 2022–14 Mar 2023 with data staging 15–16 Feb 2023 for Police Certificate, SAR, and International Child Protection Certificate forms covering up to 10,920 subjects. ICO found UK GDPR Article 32 security failings; insufficient logs left exfiltration uncertain. recordsAffected 10920 from ICO maximum potentially affected. Catalogued on 2026 reprimand disclosure date.
Root cause
Three compromises of ACRO customer portal (Kentico CMS) Jul 2021–Jun 2023 including SQLi and prolonged CMS access with data staged for exfiltration; ICO reprimand Aug 2026 for UK GDPR Art. 32 failures