← Back to Feed

Three intrusions at UK criminal records office went undetected for two years

August 12, 2026 · The Record · Severity: CRITICAL

Three separate data breaches at Britain's ACRO criminal records office went undetected for two years due to unread antivirus alerts and an unpatched content management system. A reprimand notice revealed the security lapses that exposed sensitive criminal records data. The incidents underscore the consequences of neglecting basic cybersecurity hygiene.

Key Takeaways

  • Unread antivirus alerts allowed three breaches at UK criminal records office to go undetected for two years.
  • An unpatched content management system was a key vulnerability exploited in the intrusions, per a reprimand notice.
  • The breaches highlight critical failures in security monitoring and patch management at a sensitive government agency.
☕ Buy a Coffee