The UK Criminal Records Office (ACRO) has officially admitted that it suffered a cyberattack, however it remains silent on whether it was indeed a ransomware attack.

Leading cybersecurity experts, such as Jake Moore from ESET's Global Security Division and Kevin Beaumont – head of the Security Operations Center at Arcadia Group Ltd. – believe that ACRO fell victim to a ransomware attack.
The UK Criminal Records Office (ACRO) recently experienced a major cyber incident, which led to the suspension of its customer portal. This unfortunate situation has disrupted a number of functions that rely on ACRO’s services, in particular the processing of the supply of police certificates – a key part of the visa application process .
According to ESET’s global security consultant, Jake Moore, ACRO likely fell victim to a ransomware attack, partly due to the perpetrators’ intent to steal data. Furthermore, Kevin Beaumont – head of the Security Operations Center at Arcadia Group Ltd – echoed this view and believes that the cyberattack caused by ransomware.
What is ACRO?
ACRO is the UK's main policing agency, tasked with overseeing criminal records data and verifying citizens wishing to work or live abroad. These documents are exchanged between foreign governments to process visa applications and shared with UK police forces and companies.
The agency has collected a decade’s worth of data, including names, extended family information and address records. It also includes new overseas addresses, passport details, legal representative details, photographs, PIN warnings associated with the data, and convictions or charges filed against an individual. Information relating to arrests and reprimands is also part of this significant collection.
It can also check individuals for any records, such as warnings, prosecutions or convictions. This is particularly useful for companies looking to recruit staff and embassies assessing visa applications. The data is taken directly from the UK through a contract with the Cabinet Office.

ACRO confirms security breach
Cybercriminals targeted ACRO on January 17, 2023, and continued to do so until March 21. Since then, the organization has provided hints about the dire state of its cybersecurity – such as claiming that a technical issue caused its website to go down on February 19 – and fifteen days later reporting an inability to properly process police certificates.
On March 21, the organization attributed the website problems to necessary maintenance and encouraged its customers to show understanding in dealing with any technical difficulties.
For two months, ACRO's website has been experiencing a security breach and user data has been compromised. This week, the organization sent an email to those affected by the incident, sharing that while there is no evidence of any actual breaches , they suspect that some information, including ID numbers and criminal records, may have been accessed
Realizing the security breach, the organization quickly took down its customer portal and is now processing police certificates via email manually. In order to investigate this incident, ACRO is working with various national agencies in an effort to find a solution as soon as possible.
Information source: hackread.com
