Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 16, 2026 · 6 min read

UK Criminal Records Office Hacked 3 Times Unnoticed

Three separate intrusions at ACRO between July 2021 and June 2023, one of them lasting seven months. Nearly 11,000 people had their records staged for theft. The Information Commissioner's Office issued a reprimand and no fine.

ACRO is the national policing unit that handles criminal record information held on the Police National Computer. Most of the people in its systems are not suspects. They are applicants: someone emigrating, someone taking a job that requires a certificate, someone who needs a document proving what is and is not on their record. Which makes ACRO's holdings a specific and unpleasant category of data. Not what you bought, not where you were, but what the state has written down about you, in a file you asked it to produce.

Key Takeaways

  • Three separate intrusions hit ACRO between 9 July 2021 and 22 June 2023, and none of them were detected while they were happening.
  • The most serious attacker held access from August 2022 to March 2023, seven continuous months inside the environment.
  • Nearly 11,000 people had sensitive information staged for exfiltration during that period, and more than 84,000 applicants were notified in April 2023.
  • Contributing failures included unpatched Kentico vulnerabilities, a SQL injection that exposed employee credentials, and antivirus alerts for the credential dumping tool Mimikatz that nobody acted on.
  • The Information Commissioner's Office issued a reprimand with no financial penalty, treating network segmentation that kept attackers away from core systems as a mitigating factor.

What Happened Inside ACRO?

Three intruders, on overlapping schedules, in a window running from July 2021 to June 2023. The Record's account of the incidents identifies the most serious as a group that established access in August 2022 and kept it until March 2023.

Seven months is the number to sit with. That is not a smash and grab. It is enough time to map an environment, learn which systems hold what, harvest credentials, and choose what to take. During that period nearly 11,000 people's records were assembled and staged for exfiltration, which is the step immediately before removal.

The disclosure did not come from detection. It came in April 2023 after journalists made contact, and 84,000 people who had submitted applications in the at risk window were notified then. More than 40 of them filed formal complaints. A breach that surfaces because a reporter phones is a breach the organisation was not going to find on its own.

Why Did Nobody Notice for Two Years?

Because the alerts fired and no one owned them. The most damning detail in the account is that antivirus flagged Mimikatz, and the detections were not acted on.

Mimikatz is not ambiguous. It is a credential dumping tool, it exists to extract passwords and tickets from memory, and it has essentially no legitimate reason to be running on a production server in a policing unit. An alert naming it is not a signal that needs triage against a noisy baseline. It is the security equivalent of a smoke detector in a room with no kitchen.

The other named failures are the mundane kind that compound. Kentico, the content management platform in use, had known vulnerabilities that went unpatched. A SQL injection exposed employee credentials. And responsibility for patch management was unclear between ACRO and its suppliers, which is the organisational failure that produces the technical ones. When two parties each believe the other is applying updates, nobody is, and the gap does not announce itself until somebody walks through it.

A quiet government records room with rows of grey metal filing cabinets and a closed server cabinet at the end of the aisle, lit by daylight from a high window

Why Did the ICO Issue Only a Reprimand?

Because ACRO is a public body, and because segmentation limited the blast radius. The regulator weighed the fact that attackers never reached core policing systems and concluded that a reprimand, with no financial penalty, was proportionate.

Two things can be true here. The segmentation genuinely worked, and it is the reason this story is about 11,000 staged records rather than the Police National Computer itself. That is real engineering credit and it should be acknowledged. But a reprimand is also the outcome the UK's regulator reaches for whenever the organisation at fault is public sector, and the effect over time is a two tier enforcement regime. A private company that ignored Mimikatz alerts for seven months while handling criminal record data would be looking at a very different letter.

The contrast with the enforcement wave elsewhere is stark. Regulators in Europe have been raising penalties across the board, and South Korea fined KT $39 million for concealing a breach earlier this year. The lesson a public body draws from a reprimand is that the cost of not looking at the alerts is roughly the cost of a letter.

Who Is Actually at Risk Here?

Applicants, not officers. The people affected submitted paperwork to ACRO because they needed something: a visa, a work permit, a certificate for a job abroad. Many were emigrating. Some were leaving situations they had reasons to leave.

A criminal record certificate application ties a full identity to a home address, a date of birth, an application reason and the outcome. For a person with a record, exposure is a straightforward blackmail lever. For a person with a clean record who applied for a sensitive posting, the application itself reveals intent, timing and destination. That is a category of information that does not become harmless with age, which is what separates it from a leaked shopping history.

Police adjacent data has been a recurring target all year. In the UK alone, ExfilSquad leaked 135,000 police work email addresses from a Department for Education database, and elsewhere a Swiss government SharePoint hack reached 200 accounts. The pattern is not that policing systems are uniquely weak. It is that the peripheral systems around them, the application portals and the records offices, are treated as administrative rather than sensitive.

What Can You Do If You Applied?

  • Make a subject access request. If you applied to ACRO between July 2021 and June 2023 and never received a notification, you are entitled to ask what the organisation holds about you and whether your record was in scope.
  • Treat any mail referencing your application as hostile until proven otherwise. An attacker holding an application record can write a message that quotes your reference number and your address. Verify through a channel you found yourself.
  • Watch for extortion framing rather than fraud framing. Criminal record data is leverage, not currency. The approach will look like a threat to disclose rather than a request for a payment detail.
  • Reduce what your inbox reports back. Mail sent to a leaked address arrives instrumented. Our explainer on spotting tracking pixels in Gmail shows how to see when a message is confirming that you read it.

The Uncomfortable Conclusion

The technology in this story mostly worked. Antivirus caught Mimikatz. Segmentation held the line at the core systems. The failures were in who was watching the console, who owned the patching contract, and who decided that an alert naming a credential dumping tool could wait.

The contrast with Latvia is instructive. When hackers took the vehicle registry there, the agency's entire board resigned within 11 days. ACRO's three undetected intrusions cost nobody their job.

Detection you do not read is not detection, it is logging. And a regulator that answers seven months of ignored alerts on criminal record data with a letter has priced that distinction at zero.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.