The UK's criminal records office, ACRO, has received a regulatory reprimand after security failings potentially exposed highly sensitive data belonging to nearly 11,000 people, according to The Register, citing findings from the Information Commissioner's Office (ICO). The regulator did not impose a financial penalty. ACRO disclosed a “cybersecurity incident” in April 2023 and said at the time that it had no evidence data had been compromised, The Register reports. The ICO's findings now give a more detailed picture: attackers had persistent access to ACRO's website and its Kentico content management system for more than seven months, and staged sensitive data for possible exfiltration. The Register's summary says ACRO still cannot tell whether information was exfiltrated. The most serious intrusion began on August 5, 2022, and lasted until March 14, 2023, according to the report. It was discovered only because ACRO was investigating a separate SQL injection attack in March 2023. That separate incident compromised 15 sets of credentials, most of them belonging to ACRO staff. The ICO found evidence of other intrusions dating back to July 8, 2021, The Register reports. The incidents fell into three categories: some did not affect personal data, some exposed only a small number of account credentials, and the most serious involved ACRO's website and Kentico CMS. The patching failure is central to the regulator's account. ACRO ran Kentico CMS version 12.0.0 from September 2019 until March 2023 without applying patches and hotfixes released during that period, leaving known vulnerabilities unresolved, according to The Register's account of the ICO findings. The ICO also pointed to weak operational ownership between ACRO and its managed service provider. The supplier reportedly did not learn that patching was its responsibility until February 2020 and continued to assume it did not need to actively monitor for security updates. ACRO also lacked a documented policy covering Kentico CMS patching and could not show how vulnerabilities were identified or prioritized. The report adds that ACRO's Trend Micro antivirus generated alerts, but they were apparently not acted on. That detail matters because the failure was not only a missed patching cycle; it was also a monitoring and escalation problem around a system handling sensitive public-sector data. The ICO's choice of a reprimand rather than a fine is also material. The Register notes that UK data protection penalties can reach up to £17.5 million, or 4% of an organization's total worldwide annual turnover, whichever is higher, but reprimands are a lesser enforcement tool and are often used for public-sector bodies to avoid draining public funds. Who benefits: There is no obvious commercial winner from the report. Organizations that formalize patch responsibility and alert-handling processes are better positioned to avoid the kind of control gaps the ICO identified. Who's exposed: ACRO is exposed reputationally and operationally, particularly because it still cannot tell whether staged data was exfiltrated, according to The Register. People whose sensitive data was potentially exposed also remain affected by that uncertainty.