Criminal Records Office (ACRO) hit by data theft breach
Incident
Summary
Hide ▲
Show ▼
The Criminal Records Office (ACRO) suffered an unauthorized-access breach that exposed sensitive records for 10,920 victims and put criminal-record data at risk. The intrusion ran from August 2022 to March 2023 and affected ACRO’s website and content management system (CMS). Exposed information included National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal offence data. The breach created lasting privacy and identity-theft risk even though full exfiltration could not be confirmed.
Related Happenings
ICO reprimand of ACRO for GDPR breach
Regulatory/Legal Action
H score31
First: 13.08.2026 11:30
Last: 13.08.2026 11:30
Sources 1
How related:
The UK’s data protection watchdog has issued a reprimand to the Criminal Records Office (ACRO) after multiple security failings led to a 2023 data breach which impacted over 10,000 people.
About this happening:
The ICO issued a reprimand to ACRO over GDPR infringement tied to a 2023 data breach that affected over 10,000 people. The breach involved unauthorized acc...
ICO reprimand of ACRO for GDPR breach
Regulatory/Legal ActionHow related: The UK’s data protection watchdog has issued a reprimand to the Criminal Records Office (ACRO) after multiple security failings led to a 2023 data breach which impacted over 10,000 people.
About this happening: The ICO issued a reprimand to ACRO over GDPR infringement tied to a 2023 data breach that affected over 10,000 people. The breach involved unauthorized acc...
23AndMe hit by network compromise
Incident
H score55
First: 16.07.2026 16:47
Last: 16.07.2026 16:47
Sources 1
About this happening:
23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...
23AndMe hit by network compromise
IncidentAbout this happening: 23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...
Latest development: 17.07.2026 17:30
23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.
South Staffordshire Water Plc customer data exposed after South Staffordshire Water Plc breach
Data Leak
H score57
First: 12.05.2026 23:17
Last: 12.05.2026 23:17
Sources 1
About this happening:
South Staffordshire Water Plc's data leak exposed the personal information of 663,887 customers and employees, increasing the risk of fraud and account abuse. The exposure...
South Staffordshire Water Plc customer data exposed after South Staffordshire Water Plc breach
Data LeakAbout this happening: South Staffordshire Water Plc's data leak exposed the personal information of 663,887 customers and employees, increasing the risk of fraud and account abuse. The exposure...
Timeline
-
13.08.2026 11:30 2 articles · 2h ago
ICO reprimands ACRO over a 2023 data breach
Legal Policy Action UpdateThe UK Information Commissioner’s Office reprimanded the Criminal Records Office (ACRO) after multiple security failings led to a 2023 data breach that impacted over 10,000 people. A hacker gained unauthorized access to ACRO’s website and Kentico CMS between August 2022 and March 2023, and the ICO said poor patch management and unreviewed Trend Micro malware alerts contributed to the compromise. The regulator said ACRO later decommissioned compromised infrastructure, migrated services elsewhere, implemented security monitoring, improved cyber threat visibility, and strengthened network segmentation.
Show sources
- ICO Reprimands Criminal Records Office After 2023 Breach — www.infosecurity-magazine.com — 13.08.2026 11:30
- ICO Reprimands Criminal Records Office After 2023 Breach — www.infosecurity-magazine.com — 13.08.2026 11:30