ICO Reprimands ACRO: Compromised CMS Endangers 10,920 People

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/6 · Initial Access

The attacker most likely gained access to the public-facing ACRO customer portal via an unpatched Kentico vulnerability.

T1190 – Exploit Public-Facing Application
  • Affected: customer portal www.acro.police.uk on Kentico CMS 12.0.0
  • System ran from 09/2019 to 03/2023 without a single security hotfix
  • ICO rates initial access via unpatched Kentico flaw as 'highly likely'
  • Matching reference vulnerability: CVE-2019-10068 (RCE via deserialization, fixed in 12.0.15) – not confirmed by ICO
PHASE 2/6 · Persistence

The attacker maintained undetected access to the website and CMS environment for over seven months.

  • Largest incident ('Group A') lasted from 05 Aug 2022 to 14 Mar 2023
  • Unclear patch responsibility split between OS provider and web development contractor
  • No documented CMS patching policy in place
PHASE 3/6 · Credential Access

The attacker attempted to harvest credentials with the password-dumping tool Mimikatz, but the alerts were ignored.

T1003 – OS Credential Dumping T1588.002 – Obtain Capabilities: Tool
  • On 23 Feb 2023 Trend Micro blocked four attempts to install Mimikatz
  • Security software detected and quarantined several attacker tools
  • According to ICO these alerts were not reviewed or acted upon
PHASE 4/6 · Collection

Sensitive personal data was staged for potential exfiltration.

T1074 – Data Staged
  • On 15 and 16 Feb 2023 data was staged for possible exfiltration
  • Affected: police certificates, subject access requests and international child protection certificates
  • Data types: identity, financial, biometric and criminal data plus special categories
  • Potentially affected: up to 10,920 individuals
PHASE 5/6 · Exfiltration

Whether the staged data was actually exfiltrated remained unclear due to missing log data.

T1041 – Exfiltration Over C2 Channel
  • ACRO could not determine whether data left the network
  • Log data had not been retained sufficiently
  • As a precaution ACRO notified a total of 84,048 individuals in April 2023
PHASE 6/6 · Impact & Containment

Network segmentation prevented a pivot into core police systems; ACRO was reprimanded by the ICO for security failings.

  • Network segmentation demonstrably prevented lateral movement into core police systems
  • Customer portal taken offline on 21 Mar 2023, infrastructure decommissioned on 22 Jun 2023
  • ICO found breaches of UK GDPR, in particular Article 32
  • Formal reprimand dated 07 Aug 2026, published 12 Aug 2026
Short & clear answers
Frequently asked questions about this incident
As a website operator, am I affected by this incident?
Only ACRO's installation in the UK was directly affected. However, your own risk increases if you run a publicly accessible CMS handling personal data, use an unsupported system such as Kentico 12.x, or if it is unclear who applies security updates. What matters is your specific data holdings, patch level, access rights, and your ability to respond.
Is my Kentico CMS insecure if I'm still running version 12?
Kentico 12.x is no longer supported by the vendor as of 2026 and should be treated as a migration risk. The specific vulnerability CVE-2019-10068 affects Kentico 12.0.x before version 12.0.15 and can, under certain conditions, allow code execution without authentication. Have your version and hotfix level confirmed in writing by your administration, development, or hosting team.
What do I need to do right now?
Create an inventory of all publicly accessible websites, portals, and forms, and assign a responsible owner to each component. Check your CMS version and patch history, review your logs for anomalies, and map which personal data is processed and stored where. If you see concrete signs of an attack, activate your incident response immediately and preserve evidence before any cleanup.
Why did the attack on ACRO go unnoticed for seven months?
The breach succeeded not through a sophisticated attack but through organizational gaps: it was unclear who was responsible for CMS security updates, and no hotfix was applied for years. In addition, alerts from the Trend Micro security software—such as four blocked Mimikatz attempts on 23 February 2023—were not reviewed or acted upon.
What is the key lesson from the ACRO incident for small businesses?
Define clearly and in writing who is responsible for identifying and applying security updates—even when hosting is outsourced. Also ensure that alerts are actually acted upon and that log data is retained long enough. At ACRO, missing logs meant it was impossible to determine afterwards which data had actually been exfiltrated.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.