UK Criminal Background Checker APCS Faces Data Breach Linked to Third-Party Software Provider

Outlook, the Register, reported that Access Personal Checking Services (APCS), a leading UK provider of criminal record checks, is responding to a significant data breach that originated with a third-party software developer. The Hull-based company Intradev, which provides bespoke software solutions to businesses ranging from small enterprises to household names, was the initial target of the attack.

APCS, which processes Disclosure and Barring Service (DBS) checks for over 19,000 organizations, confirmed it had alerted customers about the compromise. The checks are essential for roles involving children, vulnerable adults, healthcare, and financial services. While the full scale of affected clients is unclear, APCS reassured users that financial information does not appear to have been accessed.

Intradev’s managing director, Steve Cheetham, said the breach was detected on August 4 and is currently under investigation. “This incident involved unauthorised malicious activity with our systems and is being treated as a significant IT incident,” he said. “Initial containment measures were implemented immediately. We are reviewing the affected files and systems to understand the scope and impact of the data involved.”

Although Cheetham did not confirm whether ransomware was involved, he explained that personal data such as passport, driving license, and national insurance details may have been exposed. The exact impact varies for each individual, depending on the information provided to APCS and its upstream systems.

Intradev has reported the incident to the Information Commissioner’s Office (ICO) and Action Fraud and continues to cooperate fully with authorities. The ICO confirmed that Intradev self-referred and is under investigation.

This breach underscores the risks associated with third-party software providers, particularly for services handling sensitive personal data. Organizations using external systems for DBS or similar checks should review their own security protocols and remain vigilant for suspicious activity.

For individuals affected, APCS has advised monitoring accounts and reporting any suspicious communications. While financial data appears safe, identity theft precautions are recommended given the exposure of personal identification documents.

Source: https://www.theregister.com/2025/08/22/apcs_breach/