The UK Criminal Records Office (ACRO) has reportedly been battling a “cyber incident” for two months, creating a backlog of visa applicants and potentially putting customer information at risk.
The National Police Force checks police records of British citizens who wish to work or live abroad.
However, he has struggled to recover from the cyber-events since January 17th. evening standardEmails sent to customers affected by operational issues reportedly claimed their data may have been exposed.
This means sensitive data, including “identity and conviction data,” can end up in the hands of extortionists.
various tweets A hint to unit issues from ACRO since January. On February 9, he blamed “technical problems” for the website outage, and two weeks later he was forced to process police certificates due to “massive demand.” I argued that it was taking time.
By March 21, ACRO had reverted to blaming “critical website maintenance” for the website outage. A memo on the official site asks for customers’ patience to “resolve technical issues” and asks applicants to send an email to the office.
Ransomware Breakdown: A quarter of UK SMBs hit by ransomware in 2022.
“We are aware of a cybersecurity incident affecting the ACRO Criminal Records Service website and are working with national agencies to fully investigate it. We take data security very seriously. We take it seriously and took our customer portal offline as soon as we became aware of the incident,” the spokesperson said. evening standard.
“At this time, there is no conclusive evidence that personal data has been affected by cybersecurity incidents.”
The case has reportedly already caused a significant backlog in the processing of vital police certificates, without which applicants cannot obtain many foreign work or residence visas.
Jake Moore, Global Security Advisor at ESET, argued that ransomware was the most likely cause of the incident, but that the attacker’s main goal may have been just to steal data. Added.
“Over the last few years, attackers have turned their attention to compromising some or all of the data, as high-quality ransomware is often very difficult to create,” he added.
Trevor Dearing, Director of Critical Infrastructure Solutions at Illumio, argued that organizations should be able to withstand a breach with minimal impact on operations.
“ACRO has not disclosed the nature of the cyber incident. However, once a breach occurs in a network, it can spread rapidly throughout the system before being detected,” he said.
“The challenge is that it is often too late to detect such an attack at this point, so it is critical that organizations shift their focus to containment of the breach. By limiting , it means ring-fencing and protecting high-value applications and data.”