Exposed: Woeful security at UK criminal records office that led to sensitive data leak
- ID
- 13506
- Status
- summarized
- Published
- 12 Aug 2026, 9:40 PM
- Fetched
- 12 Aug 2026, 10:36 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/08/12/exposed-woeful-security-at-uk-criminal-records-office-that-led-to-sensitive-data-leak/5286736
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 4.5
- Created
- 12 Aug 2026, 10:38 PM
- Tags
- Audience
- developerssaas_founders
What happened
The UK's criminal records office (ACRO) was reprimanded by the ICO after attackers maintained persistent access to its Kentico CMS v12.0.0 for over seven months (Aug 2022–Mar 2023), potentially exposing data on ~11,000 people. The root cause was running an unpatched CMS from September 2019 to March 2023, compounded by a miscommunication where the managed service provider didn't learn patching was its responsibility until February 2020 and still didn't actively monitor for vulnerabilities.
Why it matters
If you outsource infrastructure or CMS management to an MSP, get the patching responsibility in writing and verify it's actually happening—ACRO's breach was caused entirely by an unpatched CMS and unclear ownership. Founders running any CMS (WordPress, Kentico, Drupal) should check whether patching is explicitly assigned in their vendor contracts and whether someone is actually applying hotfixes, not just assuming the MSP handles it.
Discussion angle
The MSP responsibility gap is the real story—how do you contractually and operationally verify your vendor is patching when neither side has explicitly claimed ownership?