Backlogs of visa applications are waiting for criminal clearance after the cyber-incident impacted services for two months at ACRO.
The unit checks criminal records of UK citizens applying for Visas abroad, but now they have to rely on email services due to the ongoing effects of the incident.
ACRO identified the incident occurred from 17 January to 21 March and impacted services throughout, though they only just sent an email to affected users alerting them to the issues.
Currently, the website is down, blaming technical issues – this was the same case on 9 February during the ongoing incident, where they organisation blamed ‘heavy demand’ for service delays.
Impacted customers were notified via email that their data may have been exposed, potentially including “identification information and any criminal conviction data.”
“At this time, we have no conclusive evidence that personal data has been affected by the cybersecurity incident; however it is only right that we inform you of the situation. We are very sorry that because of your interaction with ACRO your data could have been affected, and we are working tirelessly to resolve this matter.
“As soon as ACRO was made aware of this incident, we took robust action to take the customer portal offline so that we could fully investigate,” the email, which was seen by El Reg and the Evening Standard, said.
While there was no evidence that payment data was accessed, data about a nominated endorser, professional or other third party tied to an application may have been accessed, including their name, relationship to an applicant, occupation, phone numbers, email address, and case reference number.
Recommended
- Scots Rural Fibre Firm Secures £20M to Boost Targeted Rollout
- Ofcom Proposes to Refer UK Cloud Market for Investigation
- Scot-Secure 2023 | Security Through Anonymisation
Those who received the email include direct applications and third partiers who were nominated endorsers or administrators.
ACRO has informed the ICO and is currently working with the National Cyber Security Centre (NCSC) to investigate the incident.
The organisation is also urging those using the service for Visa applications to remain patient as they work through a backlog, manually processing applications.





