The UK's criminal records office, ACRO, has been criticized for its handling of a major cybersecurity incident that potentially exposed sensitive data of nearly 11,000 people. The incident is a stark reminder of the importance of robust security practices and effective communication between organizations and their service providers.
Key Insights
ACRO's website and content management system were compromised for over seven months, allowing attackers to stage sensitive data for possible exfiltration. The breach was caused by poor communication between ACRO and its managed service provider, and a lack of documented policies for patching and vulnerability management, resulting in the potential exposure of police certificate applications and biometric data.







