Full Report
Nobody patched the CMS or read the alerts, and ACRO still cannot tell whether info was exfiltrated
Analysis Summary
# Incident Report: Persistent CMS Compromise at ACRO Criminal Records Office
## Executive Summary
Between August 2022 and March 2023, the UK’s ACRO Criminal Records Office suffered a prolonged security breach due to unpatched software and unmonitored security alerts. Attackers maintained access for over seven months, staging highly sensitive personal and criminal record data belonging to nearly 11,000 individuals for exfiltration. While the organization has since decommissioned the infrastructure and improved its posture, the lack of logging and oversight means it remains impossible to confirm if the staged data was successfully stolen.
## Incident Details
- **Discovery Date:** March 14, 2023
- **Incident Date:** July 2021 (Initial minor intrusions); August 5, 2022 (Major CMS compromise)
- **Affected Organization:** ACRO Criminal Records Office (UK)
- **Sector:** Law Enforcement / Public Sector
- **Geography:** United Kingdom
## Timeline of Events
### Initial Access
- **Date/Time:** August 5, 2022
- **Vector:** Exploitation of known vulnerabilities in Kentico CMS.
- **Details:** ACRO was running Kentico version 12.0.0, which had not been patched or updated since September 2019.
### Lateral Movement
- **Details:** While the attackers maintained persistent access to the CMS environment for seven months, network segmentation successfully prevented movement into ACRO’s broader internal network.
### Data Exfiltration/Impact
- **Date:** February 15–16, 2023
- **Details:** Attackers gathered and staged sensitive data for exfiltration. Due to poor logging, it is unknown if the transfer was completed. Data included Police Certificates, SAR forms, Biometric data, and criminal offense history.
### Detection & Response
- **Discovery:** Detected on March 14, 2023 (following an investigation into a separate SQL injection attack).
- **Response Actions:** The website was taken offline; a third-party forensic firm was hired; the Information Commissioner’s Office (ICO) was notified; 84,048 individuals were initially alerted.
## Attack Methodology
- **Initial Access:** Exploitation of unpatched vulnerabilities in Kentico CMS (v12.0.0).
- **Persistence:** Maintained access for 221 days (August 2022 to March 2023).
- **Defense Evasion:** Exploited a "blind spot" caused by unmonitored security alerts.
- **Discovery:** Internal reconnaissance of the CMS database and file system.
- **Collection:** Staging of sensitive documents and personal data in mid-February 2023.
- **Impact:** Potential data breach of 10,920 highly sensitive records; significant reputational damage.
## Impact Assessment
- **Financial:** Escaped a monetary fine (ICO issued a reprimand), but incurred costs for third-party forensics and infrastructure migration.
- **Data Breach:** 10,920 individuals had data staged for theft. Records included National Insurance numbers, bank details, biometric data, and criminal convictions.
- **Operational:** Website taken offline for months; decommissioning of legacy infrastructure.
- **Reputational:** 35 formal complaints regarding distress and risk of identity theft; public reprimand by the ICO.
## Indicators of Compromise
- **Network:** [Not disclosed in detail, but involved traffic to/from the Kentico CMS host]
- **File:** Staged data files created between Feb 15-16, 2023.
- **Behavioral:** High-volume SQL injection attempts; Trend Micro antivirus alerts (which were generated but ignored).
## Response Actions
- **Containment:** Website taken offline immediately upon discovery in March 2023.
- **Eradication:** Compromised infrastructure decommissioned in June 2023.
- **Recovery:** Migration to a new platform; implementation of a Security Operations Center (SOC).
## Lessons Learned
- **Patch Management Failure:** A lack of clarity between ACRO and its Managed Service Provider (MSP) led to a three-year gap in security updates.
- **Alert Fatigue/Negligence:** Security software (Trend Micro) functioned correctly, but no personnel were assigned to review or act on the alerts.
- **Logging Deficiencies:** Inadequate logging prevented investigators from determining if data exfiltration actually occurred.
## Recommendations
- **Clear Accountability:** Establish a Responsibility Assignment Matrix (RACI) with MSPs to ensure patch management duties are explicitly defined.
- **Centralized Log Management:** Implement robust logging to ensure a clear audit trail for forensic investigations.
- **Active Monitoring:** Ensure all security alerts are triaged by a SOC or a designated internal security team.
- **Vulnerability Scanning:** Conduct regular automated scans to identify end-of-life or unpatched software versions.