CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Three intrusions at UK criminal records office went undetected for two years

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4327

As cited

Copy frozen at (site build).

breaches incidents

Three intrusions at UK criminal records office went undetected for two years

Three separate intrusions at the UK's ACRO (criminal records office) remained undetected for two years due to unread antivirus alerts and an unpatched content management system, according to a regulatory reprimand. The breaches highlight gaps in monitoring and patch management at a sensitive government agency.

Why it matters: UK government staff, criminal justice users, and potentially crime victims were exposed; practitioners should review alert triage processes and patch cadences for critical systems handling sensitive data.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary