Dyfed-Powys Police confirms cyberattack, staff data potentially accessed

Emergency services unaffected but non-emergency systems disrupted since September 14; investigation ongoing

By LineZotpaper
Published
Read Time2 min
Dyfed-Powys Police has revealed it was hit by a cyberattack on September 14 that knocked some of its systems offline, with investigators now trying to determine whether intruders accessed staff data. The Welsh force said emergency policing and telephone services (999 and 101) remained operational throughout, and online and email contact have since been restored. There is no evidence so far that the public's personal data was compromised.

The force disclosed the incident on Thursday, stating that it identified the attack on September 14 and caused disruption to some non-emergency systems. Cybersecurity specialists were brought in and "precautionary measures" applied to systems while teams worked to restore services safely.

In a statement, Dyfed-Powys Police said: "At this stage, our investigation has found no evidence that members of the public's personal data has been accessed or compromised as a result of this incident. We are, however, continuing to investigate whether any information relating to our staff may have been accessed or compromised, and are taking all appropriate steps to protect that information, and will provide appropriate advice to colleagues if required."

The force notified the Information Commissioner's Office (ICO), though it did not specify when. The investigation is being managed by Tarian, the regional organised crime unit covering three southern Welsh police force areas, through its regional cybercrime unit.

There is no indication yet of who was behind the attack, how they gained entry, or whether ransomware was involved. Dyfed-Powys Police did not respond to requests for additional details.

§

Analysis

Why This Matters

  • The breach of a police force's systems raises concerns about the security of sensitive law enforcement data, particularly staff information that could include personal details, vetting records, or operational roles.
  • If staff data has been stolen, affected individuals may face risks of identity theft or targeted phishing campaigns.
  • The incident underscores ongoing cybersecurity vulnerabilities within UK public sector organisations, which have been frequent targets of ransomware and data theft attacks.

Background

Dyfed-Powys Police serves a large rural area of mid and west Wales. Like many UK police forces, it relies on a mix of legacy and modern IT systems for both emergency response and administrative functions. Cyberattacks on UK police forces have occurred in recent years, with some resulting in significant data breaches. The ICO has previously fined public bodies for failing to protect personal data.

Key Perspectives

Dyfed-Powys Police: The force's priority is to restore systems safely and protect data. It has been transparent about the incident so far, proactively notifying the ICO and updating the public. It stresses that emergency services were never compromised. Staff and unions: Officers and civilian staff may be concerned about their personal data being exposed, especially if it includes sensitive information such as addresses, pay details, or disciplinary records. Police federations often press for swift updates and support measures. Critics/Skeptics: Questions remain about the full extent of the breach, how long the attackers had access before detection, and whether the force's cybersecurity measures were adequate. Without independent verification, some may doubt the claim that no public data was accessed.

What to Watch

  • The ICO's assessment and any regulatory action if data was compromised.
  • Whether the attackers claim responsibility or attempt to leak data, which would confirm the scope.
  • Updates from the Tarian cybercrime unit on the investigation's progress and any arrests.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.