Skip to Primary Navigation

UK’s ICO reprimands Criminal Records Office for cyber failings

A crime scene in UK
The breach is said to have taken place between August 2022 and March 2023. Photo: Ashley Cooper/Getty Images

Following the incident the information watchdog has urged organizations to strengthen patching and security monitoring processes.

The UK’s Information Commissioner has reprimanded the country’s Criminal Records Office (ACRO) for cybersecurity failings that left the personal information, including some sensitive data, of up to 10,000 people potentially compromised and exposed.

The incident took place between August 2022 and March 2023 when a hacker gained unauthorized access to the

After gaining

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience