AI Weekly Malaysia

Back to items Summaries

Exposed: Woeful security at UK criminal records office that led to sensitive data leak

ID
13506
Status
summarized
Published
12 Aug 2026, 9:40 PM
Fetched
12 Aug 2026, 10:36 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/security/2026/08/12/exposed-woeful-security-at-uk-criminal-records-office-that-led-to-sensitive-data-leak/5286736
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
4.5
Created
12 Aug 2026, 10:38 PM
Tags
Audience
developerssaas_founders

What happened

The UK's criminal records office (ACRO) was reprimanded by the ICO after attackers maintained persistent access to its Kentico CMS v12.0.0 for over seven months (Aug 2022–Mar 2023), potentially exposing data on ~11,000 people. The root cause was running an unpatched CMS from September 2019 to March 2023, compounded by a miscommunication where the managed service provider didn't learn patching was its responsibility until February 2020 and still didn't actively monitor for vulnerabilities.

Why it matters

If you outsource infrastructure or CMS management to an MSP, get the patching responsibility in writing and verify it's actually happening—ACRO's breach was caused entirely by an unpatched CMS and unclear ownership. Founders running any CMS (WordPress, Kentico, Drupal) should check whether patching is explicitly assigned in their vendor contracts and whether someone is actually applying hotfixes, not just assuming the MSP handles it.

Discussion angle

The MSP responsibility gap is the real story—how do you contractually and operationally verify your vendor is patching when neither side has explicitly claimed ownership?

Top