
ACRO Cybersecurity Failings Put Sensitive UK Records at Risk
The ICO says weak patch ownership and missed security alerts left passport, bank, biometric and criminal-record information for up to 10,920 people potentially exposed.
The short version
What you need to know
- The ICO says an attacker retained unauthorised access to ACRO's website environment between August 2022 and March 2023, potentially affecting up to 10,920 people.
- Potentially exposed records included identity-document, bank, biometric, criminal-offence and other special-category data, but ACRO could not conclusively establish whether the staged information was removed.
- A VPN cannot repair an organisation's unpatched content-management system or recover records already supplied to it; phishing vigilance and identity or financial monitoring are more relevant for affected people.
What did the ICO find?
The UK Information Commissioner's Office announced on 12 August that it had reprimanded the ACRO Criminal Records Office over cybersecurity failings. Its investigation found that an attacker gained unauthorised access to ACRO's website and content-management system between August 2022 and March 2023.
The attacker was able to stage personal information for theft. ACRO could not conclusively determine whether that information was removed, so this should be described as a potential exposure rather than proof that every affected record was stolen. Network segmentation prevented the attacker moving from the website environment into ACRO's core systems.
What information was potentially exposed?
The ICO says up to 10,920 people may have been affected. The records potentially included names, dates of birth, addresses, National Insurance numbers, passport and driving-licence details, bank-account information, biometric data, criminal-offence information and other special-category data.
Those affected included applicants for Police Certificates and International Child Protection Certificates, people making subject access requests, and some third parties connected to applications. That combination could make a targeted phishing or identity-fraud approach unusually convincing even though exfiltration was not confirmed.
What affected people can do now
Anyone contacted by ACRO should follow the official notice, but obtain contact details independently from ACRO's real website rather than trusting links or phone numbers in an unexpected message. Treat calls, texts or emails that mention a Police Certificate, passport, background check or bank details as untrusted until verified through that separate route.
Monitor relevant bank accounts and credit files, report unfamiliar activity promptly, and consider protective registration or an appropriate credit-monitoring service if ACRO's notice indicates that identity-document data was involved. Use unique passwords and strong multi-factor authentication on email, banking and government-related accounts; exposed biographical details can make password-reset impersonation more persuasive.
Where a VPN helps — and where it does not
A VPN can protect traffic between a person's device and the VPN server on an untrusted network. It does not control how a public body patches its website, investigates alerts or protects information already submitted to it.
Using a VPN now cannot erase exposed records, prevent criminals using real identity details in a scam or prove that an ACRO-themed message is genuine. The useful controls here are organisational patching and monitoring, plus careful verification, account security and proportionate identity or financial monitoring for individuals.
VPN Rocks view
The ICO identified unclear responsibility for critical CMS updates, an ineffective patch process and inadequate investigation of security alerts. Outsourcing parts of security does not outsource accountability: organisations handling sensitive records still need a named owner and evidence that warnings are acted on.
The fact that segmentation limited the intrusion is also important. Basic defensive layers can reduce harm even when another control fails, just as consumers should combine unique credentials, MFA and scepticism toward messages rather than expecting any one privacy product to solve breach exposure.
Primary reading
Sources and further reading
We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.
