← Back to Feed
Three intrusions at UK criminal records office went undetected for two years
August 12, 2026 · The Record · Severity: CRITICAL
Three separate data breaches at Britain's ACRO criminal records office went undetected for two years due to unread antivirus alerts and an unpatched content management system. A reprimand notice revealed the security lapses that exposed sensitive criminal records data. The incidents underscore the consequences of neglecting basic cybersecurity hygiene.
Key Takeaways
- Unread antivirus alerts allowed three breaches at UK criminal records office to go undetected for two years.
- An unpatched content management system was a key vulnerability exploited in the intrusions, per a reprimand notice.
- The breaches highlight critical failures in security monitoring and patch management at a sensitive government agency.