Article 77MKT Exposed: Woeful security at UK criminal records office that led to sensitive data leak

Exposed: Woeful security at UK criminal records office that led to sensitive data leak

by
from www.theregister.com - Articles on (#77MKT)
Story ImageThe UK's criminal records office, ACRO, has escaped a fine and received a regulatory reprimand after security failings potentially exposed highly sensitive data belonging to nearly 11,000 people. ACRO disclosed the "cybersecurity incident" in April 2023, and said at the time that it had no evidence to suggest that any data was compromised. However, it has now emerged that attackers maintained persistent access to ACRO's website and content management system for more than seven months, and staged sensitive data for possible exfiltration. According to the Information Commissioner's Office (ICO), which reprimanded ACRO rather than imposing a financial penalty, the breach was uncovered in March 2023 only because ACRO was investigating a separate intrusion. The watchdog said that while investigating an SQL injection attack that compromised 15 sets of credentials, most belonging to ACRO staff, investigators found evidence of separate intrusions dating back to July 8, 2021. The incidents fell into three categories, the ICO said. Some did not affect personal data, while others exposed only a small number of account credentials. The most serious involved ACRO's website and its Kentico content management system. The intrusion began on August 5, 2022, and the attackers maintained persistent access, without being detected, until March 14, 2023. The ICO found that ACRO ran version 12.0.0 of Kentico CMS from September 2019 until March 2023 without applying the patches and hotfixes released during that period, leaving known vulnerabilities unresolved. The ICO blamed poor communication between ACRO and its managed service provider. The supplier did not learn that patching was its responsibility until February 2020 and continued to assume that it was not required to monitor actively for security updates. "The ambiguity around who was accountable for identifying necessary Kentico CMS patches created a gap where patches and hotfixes were missed, which ultimately left ACRO's website vulnerable," the ICO said. Further, ACRO did not have a documented policy that covered patching Kentico CMS, nor could it demonstrate how vulnerabilities were identified or prioritized. ACRO's Trend Micro antivirus generated alerts, but nobody appears to have been minding them. The records office told the ICO that, for reasons redacted from the postmortem, it was "unable to establish what business processes existed for the assessment or handling of security alerts at the relevant time." It also could not identify which roles were responsible for reviewing these alerts at the time, ultimately resulting in them going unread. ACRO's poor logging means that, despite an extensive investigation by a third-party cybersecurity outfit, it remains impossible to determine whether the affected data was exfiltrated. Investigators did establish that the attackers staged the data for possible exfiltration between February 15 and 16, 2023. The potentially exposed material included: Police Certificate Applications Subject Access Request (SAR) forms and International Child Protection Certificate forms Names Dates of birth Addresses National Insurance numbers Passport and driving licence details Bank account information Biometric data Highly sensitive criminal offence and special category information ACRO notified 84,048 people of the breach, although investigators later determined that data relating to no more than 10,920 individuals had potentially been staged for exfiltration. Of these, ACRO received 35 formal complaints citing personal distress and concern about the risk of identity theft and financial loss, according to the ICO's reprimand document [PDF]. "Complainants included those connected to Police Certificates, International Child Protection Certificates, and victims of domestic violence." The ICO also received six complaints citing similar concerns. ACRO's saving grace was its network segmentation, which prevented the attackers from straying beyond the CMS into other systems, the ICO noted. Since the attack was discovered, ACRO has made a number of improvements to its security, including decommissioning the compromised infrastructure (although not until June 2023), implementing a SIEM, improving visibility, monitoring, and network segmentation, hardening systems, and migrating to Salesforce Experience Cloud. Jonathan Balmforth, group manager of civil and cyber investigations at the ICO, said: "This case highlights how basic cyber security failings can create significant risks for thousands of people, particularly where organizations process large volumes of highly sensitive personal information. "Organizations must ensure there is clear accountability for identifying, assessing and applying security updates. They must also have effective monitoring in place so that warning signs of cyberattacks are identified, investigated and acted upon promptly. "The lessons from this incident are clear. Having the right policies, responsibilities and oversight arrangements in place is just as important as having the right technology. "We welcome the improvements ACRO has made since these incidents. We hope other organizations will use this case as an opportunity to review their own processes and responses to ensure personal information remains properly protected." ACRO welcomed the reprimand from the ICO and highlighted the steps it has taken since to bolster its security. A spokesperson told The Register: "Since the cybersecurity incident was identified in March 2023, we have worked hard to strengthen our systems and safeguards. "In particular, we immediately took the previous website offline and subsequently decommissioned it. We also took steps to protect customers, including making sure anyone potentially affected was informed at the earliest possible stage." They went on to say: "We accept the ICO's findings of the infringements. We are grateful for the recognition from the Information Commissioner of the multiple remedial steps ACRO has taken in light of this incident and are committed to maintaining high standards of data protection and information security in future." (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments