Three intrusions at UK criminal records office went undetected for two years
The UK criminal records office, ACRO, suffered three undetected intrusions over two years due to severe security failings, including unaddressed vulnerabilities in its public-facing website and ignored cybersecurity alerts. The incidents exposed the personal data of thousands, including victims of domestic violence, and were linked to a ransomware claim by the Medusa group, though no data was publicly released. Despite a network segmentation preventing further system compromise, the ICO reprimanded ACRO for its institutional failures and lack of effective security practices.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
