ICO reprimand of ACRO for GDPR breach
Regulatory/Legal Action
Summary
Hide ▲
Show ▼
The ICO issued a reprimand to ACRO over GDPR infringement tied to a 2023 data breach that affected over 10,000 people. The breach involved unauthorized access to ACRO’s website and content management system (CMS) between August 2022 and March 2023. The exposure included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and criminal-offence information. The reprimand centers on poor patch management and insufficient security monitoring.
Related Happenings
Criminal Records Office (ACRO) hit by data theft breach
Incident
H score37
First: 13.08.2026 11:30
Last: 13.08.2026 11:30
Sources 1
How related:
Between August 2022 and March 2023, a hacker gained unauthorized access to ACRO’s website and content management system (CMS), according to the Information Commissioner’s Office (ICO).
About this happening:
The Criminal Records Office (ACRO) suffered an unauthorized-access breach that exposed sensitive records for 10,920 victims and put criminal-record data at risk. The i...
Criminal Records Office (ACRO) hit by data theft breach
IncidentHow related: Between August 2022 and March 2023, a hacker gained unauthorized access to ACRO’s website and content management system (CMS), according to the Information Commissioner’s Office (ICO).
About this happening: The Criminal Records Office (ACRO) suffered an unauthorized-access breach that exposed sensitive records for 10,920 victims and put criminal-record data at risk. The i...
23AndMe multistate genetic-data settlement and ICO fine
Regulatory/Legal Action
H score35
First: 16.07.2026 16:47
Last: 16.07.2026 16:47
Sources 1
About this happening:
23andMe agreed to pay $18 million to settle multistate claims over its failure to protect customers' genetic data, extending the legal fallout from the 2023 breach. Re...
23AndMe multistate genetic-data settlement and ICO fine
Regulatory/Legal ActionAbout this happening: 23andMe agreed to pay $18 million to settle multistate claims over its failure to protect customers' genetic data, extending the legal fallout from the 2023 breach. Re...
23AndMe hit by network compromise
Incident
H score55
First: 16.07.2026 16:47
Last: 16.07.2026 16:47
Sources 1
About this happening:
23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...
23AndMe hit by network compromise
IncidentAbout this happening: 23andMe disclosed a credential-stuffing breach that exposed data on 6.9 million customers, including genetic ancestry information. The unauthorized access ran from A...
Latest development: 17.07.2026 17:30
23andMe reached an $18m settlement with a coalition of 42 US attorneys general over the 2023 credential stuffing breach, and the agreement adds new data protection requirements for 23andMe customer data and TTAM Research.
ICO fine against South Staffordshire Water for data breach
Regulatory/Legal Action
H score69
First: 12.05.2026 11:30
Last: 12.05.2026 11:30
Sources 1
About this happening:
The ICO finalized a nearly £1m penalty against South Staffordshire Water and South Staffordshire PLC, resolving a cyber enforcement action tied to a breach that ex...
ICO fine against South Staffordshire Water for data breach
Regulatory/Legal ActionAbout this happening: The ICO finalized a nearly £1m penalty against South Staffordshire Water and South Staffordshire PLC, resolving a cyber enforcement action tied to a breach that ex...
Companies House WebFiling data exposure affecting five million registered companies
Data Leak
H score23
First: 16.03.2026 19:07
Last: 16.03.2026 19:07
Sources 1
About this happening:
A Companies House WebFiling access-control flaw exposed non-public company records to unauthorized logged-in users, creating a privacy and integrity risk for millions of filin...
Companies House WebFiling data exposure affecting five million registered companies
Data LeakAbout this happening: A Companies House WebFiling access-control flaw exposed non-public company records to unauthorized logged-in users, creating a privacy and integrity risk for millions of filin...
Timeline
-
13.08.2026 11:30 2 articles · 2h ago
ICO reprimands ACRO over GDPR breach and security failings
Legal Policy Action UpdateThe Information Commissioner’s Office reprimanded the Criminal Records Office (ACRO) after finding that poor patch management and insufficient security monitoring enabled unauthorized access to ACRO’s website and Kentico CMS between August 2022 and March 2023. The breach impacted over 10,000 people, may have exposed 10,920 victims’ sensitive data, and included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and highly sensitive criminal offence and special category information. ACRO had a Trend Micro solution installed to detect and quarantine malware, but its alerts were not reviewed or acted upon; the remedial response included decommissioning compromised infrastructure, migrating services elsewhere, implementing security monitoring, improving visibility of cyber threats, and strengthening network segmentation.
Show sources
- ICO Reprimands Criminal Records Office After 2023 Breach — www.infosecurity-magazine.com — 13.08.2026 11:30
- ICO Reprimands Criminal Records Office After 2023 Breach — www.infosecurity-magazine.com — 13.08.2026 11:30