ACRO Data Breach: Kentico CMS Attack Exposed Records

August 13, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: cypro.co.uk

Threat Risk: High
Victim: UK Criminal Records Office (ACRO)
Incident: Persistent access and data staging via unpatched Kentico CMS vulnerabilities.
Impact: Potential exposure of PII, biometric data, and criminal records for nearly 11,000 individuals.
Attacker: Unidentified threat actors
Analysis: Attackers leveraged unpatched Kentico CMS software to maintain persistent access to ACRO’s systems for over half a year. The breach was exacerbated by a failure in the shared responsibility model between the agency and its service provider. Poor logging hindered the ability to conclusively track the total volume of exfiltrated sensitive data.
Recommendations: Audit and automate patch management for all CMS and web-facing applications.; Clarify security responsibilities within Third-Party Service Level Agreements (SLAs).; Implement enhanced logging and monitoring to detect data staging activities.
Source: Cypro

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *