Dyfed-Powys Police Confirms Cyberattack, Staff Data Investigation Ongoing
Dyfed-Powys Police, the force covering southwest Wales, confirmed on Friday, September 25, 2026, that a cyberattack disrupted some of its non-emergency systems and may have compromised information belonging to its own staff. The force said it first identified the incident on Monday, September 14, 2026 — meaning roughly 11 days passed between detection and public disclosure. Dyfed-Powys Police serves more than 500,000 people across Carmarthenshire, Ceredigion, Pembrokeshire, and Powys, and employs more than 2,000 officers and staff.
A force spokesperson said the investigation "has found no evidence that members of the public's personal data has been accessed or compromised as a result of this incident," but confirmed the force is "continuing to investigate whether any information relating to our staff may have been accessed or compromised." The force has not disclosed how the attackers gained access, what systems were initially entered, or which categories of staff data may be at risk, and as of publication no threat group had claimed responsibility.
Incident Details
| Attribute | Value |
|---|---|
| Organization | Dyfed-Powys Police |
| Region Covered | Carmarthenshire, Ceredigion, Pembrokeshire, and Powys, Wales |
| Population Served | More than 500,000 |
| Staff Complement | More than 2,000 officers and staff |
| Incident Detected | Monday, September 14, 2026 |
| Publicly Disclosed | Friday, September 25, 2026 (approximately 11 days later) |
| Systems Affected | Non-emergency systems, including email and online contact channels |
| Emergency Services Impact | 999 emergency call handling remained operational throughout |
| Data at Risk | Staff information — under investigation; no evidence of public data compromise |
| Investigation Lead | Tarian regional organised crime unit (cyber-crime unit), with external cybersecurity specialists |
| Regulatory Notification | Information Commissioner's Office (ICO) notified |
| Attribution | No group has claimed responsibility as of publication |
What Happened
Detection and Initial Disruption
The force identified the cyberattack on September 14, 2026, and responded by disrupting some of its own non-emergency systems as a precautionary containment measure. Reporting indicates email and online contact services were temporarily unavailable in the aftermath, while the force's 999 emergency call-handling capability continued operating without interruption throughout the incident. The force has not specified the initial point of entry, the type of malware or intrusion technique involved, or whether any systems were encrypted, leaving key technical details of the "how" undisclosed publicly.
Staff Data Under Active Investigation
Dyfed-Powys Police has drawn a clear line between data belonging to the public and data belonging to its own workforce. The force says its investigation so far has found no evidence that members of the public's personal data was accessed or compromised, but it has not been able to rule out that staff information — potentially including personal details of officers and employees — was accessed. The force has not specified which staff data fields (such as names, contact details, payroll data, or vetting information) might be implicated, saying only that it is "taking all appropriate steps to protect that information" while the review continues.
Response and Oversight
The technical investigation is being led by Tarian, the regional organised crime unit covering southern Wales, working through its dedicated cyber-crime unit, and is being supported by outside cybersecurity specialists. The force has also notified the Information Commissioner's Office (ICO), the UK's data protection regulator, consistent with obligations that apply when personal data may have been compromised. No ransomware group or data-extortion actor had claimed the attack at the time of reporting, and the force has given no indication of whether a ransom demand was received.
Part of a Wider Pattern Targeting UK Policing
This incident lands roughly a month after a separate, unrelated breach hit the UK Police National Legal Database (PNLD), an online legal reference service used by police forces across England and Wales for more than three decades. In that case, a data-extortion group calling itself ExfilSquad claimed to have stolen 1.9 GB of material spanning roughly 135,000 records — about 114,000 PNLD subscriber accounts and around 21,000 "Ask the Police" users — and demanded payment. While Dyfed-Powys Police has not been linked to that campaign, the two incidents in close succession underscore that UK law enforcement organizations, and the personal data of their staff, have become a recurring target.
Impact Assessment
| Impact Area | Description |
|---|---|
| Operational Disruption | Non-emergency systems, including email and online contact channels, were taken offline or disrupted; 999 emergency response was not affected |
| Staff Privacy Exposure | Potential compromise of officer and employee personal information remains under active investigation |
| Public Data Exposure | No evidence found to date that public/citizen personal data was accessed |
| Targeted Phishing Risk | Security researchers warn that stolen staff details could be used to craft convincing phishing or social-engineering campaigns against police employees |
| Sector-Wide Trend | Follows the ExfilSquad-claimed PNLD breach affecting more than 100,000 police and justice professionals a month earlier, suggesting sustained targeting of UK policing |
| Regulatory Exposure | ICO notification signals the incident is being treated as a potential personal-data breach under UK data protection law |
| Reputational/Trust Impact | Delayed public disclosure (roughly 11 days after detection) may draw scrutiny over transparency timelines |
Recommendations
For Dyfed-Powys Police and Similar Forces
- Complete and publish, where legally appropriate, a clear account of the affected systems, root cause, and specific staff data categories involved once the investigation concludes, to support affected employees in taking protective action.
- Offer credit monitoring, identity-theft protection, or equivalent support to any staff confirmed to be affected, given the elevated targeting risk that comes with a law-enforcement staff roster.
- Review and, if necessary, segment non-emergency IT systems (email, web contact forms, case-management back office) from emergency call-handling infrastructure to preserve the resilience demonstrated here, where 999 services stayed online throughout.
- Coordinate with Tarian, the National Cyber Security Centre (NCSC), and the ICO to ensure consistent, timely public communication as findings develop.
For Security Teams at Other Public-Sector Organizations
- Treat any breach affecting police or justice-sector staff rosters as a precursor risk: assume attackers may attempt to leverage exposed names, roles, and contact details for follow-on phishing or impersonation against officers, their families, or partner agencies.
- Review email and web-facing contact systems for indicators of compromise consistent with initial-access techniques seen in recent UK public-sector intrusions, even absent a confirmed link to this specific incident.
- Ensure incident-response plans include a clear internal/external data-classification split (public data vs. staff/employee data) so containment and disclosure decisions can be made quickly and communicated precisely, as Dyfed-Powys Police has done here.
For Affected Staff and Officers
- Treat unexpected emails, texts, or calls referencing employer, payroll, or HR matters with heightened suspicion until the force confirms the scope of any staff data exposure.
- Enable multi-factor authentication on personal accounts that share an email address or password with work accounts, and change any reused credentials as a precaution.
- Monitor for signs of identity theft or targeted phishing attempts and report suspicious contact to force IT security and, where relevant, to Action Fraud.
Key Takeaways
- Dyfed-Powys Police disclosed on September 25, 2026 that a cyberattack detected on September 14, 2026 disrupted non-emergency systems and may have compromised staff data.
- Emergency 999 call-handling remained fully operational throughout; email and online contact channels were the systems disrupted.
- The force found no evidence that public/citizen personal data was accessed, but staff data exposure remains under active investigation.
- Tarian's cyber-crime unit is leading the technical investigation with outside cybersecurity specialist support, and the ICO has been notified.
- No group has claimed responsibility, and the force has not disclosed the attack's initial access method or technique.
- The incident follows the ExfilSquad-claimed breach of the UK Police National Legal Database roughly a month earlier, reinforcing a broader pattern of threat actors targeting UK policing and law-enforcement staff data.