ACRO has received a regulatory reprimand instead of a fine following significant security failings that potentially exposed sensitive data of nearly 11,000 individuals, according to The Register.
The Information Commissioner's Office (ICO) issued the reprimand after discovering that attackers maintained persistent access to ACRO's website and content management system for over seven months, from August 5, 2022, to March 14, 2023.
This prolonged access was facilitated by ACRO's failure to apply critical patches and hotfixes to its Kentico CMS, leaving known vulnerabilities unaddressed. The ICO cited poor communication between ACRO and its managed service provider regarding patching responsibilities, a lack of documented policies for vulnerability management, and unmonitored security alerts as key contributing factors. While the full extent of data exfiltration remains undetermined due to poor logging, attackers staged sensitive information, including names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and highly sensitive criminal offense details, for potential download.
Although ACRO initially notified over 84,000 individuals, investigations later narrowed the potential exposure to approximately 10,920 people. ACRO has since implemented several security improvements, including decommissioning the compromised infrastructure and migrating to a new system.
Source: The Register
Written by
Kelley Damore
Chief Content Officer
CyberRisk Alliance
Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.