HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Three Undetected Intrusions Exploit Unpatched Kentico CMS at UK Criminal Records Office, Exposing Thousands of Personal Records

Three separate attackers breached ACRO Criminal Records Office between July 2021 and June 2023 by exploiting an unpatched Kentico CMS and ignored security alerts, exposing personal data of thousands. The incident highlights the need for documented patch‑management and alert‑handling processes to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
therecord.media

Three Intrusions at UK Criminal Records Office Undetected for Two Years

What Happened — Between July 2021 and June 2023, three separate attackers compromised ACRO’s public‑facing portal built on an unpatched Kentico CMS. Antivirus alerts (including Mimikatz detections) were never acted on, allowing persistent access and exposure of personal data for thousands of individuals, including domestic‑violence victims.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates a classic SOC 2 control‑mapping gap: no documented process for patch management or security‑alert triage, leaving the organization unable to demonstrate the CC6.1 (System Operations) and CC6.2 (Change Management) controls.
  • Continuous evidence collection (e.g., patch‑status logs, alert‑handling tickets) is essential to prove that controls are operating effectively over time.
  • Verisq’s Control Mapping capability automates evidence capture for these controls, turning patch‑and‑alert data into audit‑ready artifacts.

Who Is Affected — Government‑public sector (national policing unit) handling sensitive criminal‑record data.

Recommended Actions

  • Formalize a patch‑management policy tied to a schedule and assign clear ownership.
  • Deploy a security‑alert workflow that logs receipt, investigation, and remediation steps.
  • Map these processes to SOC 2 criteria and begin continuous evidence collection to close the audit gap.

Technical Notes — The Kentico CMS version (unchanged since Sep 2019) contained multiple publicly disclosed vulnerabilities; none were patched. Trend Micro alerts flagged four Mimikatz installation attempts, all ignored. Source: The Record

📰 Original Source
https://therecord.media/uk-criminal-records-office-acro-data-breaches

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →