NEWS

Cyberattack Hits Welsh Police Force, May Have Affected Staff Data

Dyfed-Powys Police says a cyberattack disrupted non-emergency systems and may have compromised staff data; no evidence public data was accessed.

Dylan H.

News Desk

September 25, 2026
7 min read
Cyberattack Hits Welsh Police Force, May Have Affected Staff Data

Dyfed-Powys Police Confirms Cyberattack, Staff Data Investigation Ongoing

Dyfed-Powys Police, the force covering southwest Wales, confirmed on Friday, September 25, 2026, that a cyberattack disrupted some of its non-emergency systems and may have compromised information belonging to its own staff. The force said it first identified the incident on Monday, September 14, 2026 — meaning roughly 11 days passed between detection and public disclosure. Dyfed-Powys Police serves more than 500,000 people across Carmarthenshire, Ceredigion, Pembrokeshire, and Powys, and employs more than 2,000 officers and staff.

A force spokesperson said the investigation "has found no evidence that members of the public's personal data has been accessed or compromised as a result of this incident," but confirmed the force is "continuing to investigate whether any information relating to our staff may have been accessed or compromised." The force has not disclosed how the attackers gained access, what systems were initially entered, or which categories of staff data may be at risk, and as of publication no threat group had claimed responsibility.


Incident Details

AttributeValue
OrganizationDyfed-Powys Police
Region CoveredCarmarthenshire, Ceredigion, Pembrokeshire, and Powys, Wales
Population ServedMore than 500,000
Staff ComplementMore than 2,000 officers and staff
Incident DetectedMonday, September 14, 2026
Publicly DisclosedFriday, September 25, 2026 (approximately 11 days later)
Systems AffectedNon-emergency systems, including email and online contact channels
Emergency Services Impact999 emergency call handling remained operational throughout
Data at RiskStaff information — under investigation; no evidence of public data compromise
Investigation LeadTarian regional organised crime unit (cyber-crime unit), with external cybersecurity specialists
Regulatory NotificationInformation Commissioner's Office (ICO) notified
AttributionNo group has claimed responsibility as of publication

What Happened

Detection and Initial Disruption

The force identified the cyberattack on September 14, 2026, and responded by disrupting some of its own non-emergency systems as a precautionary containment measure. Reporting indicates email and online contact services were temporarily unavailable in the aftermath, while the force's 999 emergency call-handling capability continued operating without interruption throughout the incident. The force has not specified the initial point of entry, the type of malware or intrusion technique involved, or whether any systems were encrypted, leaving key technical details of the "how" undisclosed publicly.

Staff Data Under Active Investigation

Dyfed-Powys Police has drawn a clear line between data belonging to the public and data belonging to its own workforce. The force says its investigation so far has found no evidence that members of the public's personal data was accessed or compromised, but it has not been able to rule out that staff information — potentially including personal details of officers and employees — was accessed. The force has not specified which staff data fields (such as names, contact details, payroll data, or vetting information) might be implicated, saying only that it is "taking all appropriate steps to protect that information" while the review continues.

Response and Oversight

The technical investigation is being led by Tarian, the regional organised crime unit covering southern Wales, working through its dedicated cyber-crime unit, and is being supported by outside cybersecurity specialists. The force has also notified the Information Commissioner's Office (ICO), the UK's data protection regulator, consistent with obligations that apply when personal data may have been compromised. No ransomware group or data-extortion actor had claimed the attack at the time of reporting, and the force has given no indication of whether a ransom demand was received.

Part of a Wider Pattern Targeting UK Policing

This incident lands roughly a month after a separate, unrelated breach hit the UK Police National Legal Database (PNLD), an online legal reference service used by police forces across England and Wales for more than three decades. In that case, a data-extortion group calling itself ExfilSquad claimed to have stolen 1.9 GB of material spanning roughly 135,000 records — about 114,000 PNLD subscriber accounts and around 21,000 "Ask the Police" users — and demanded payment. While Dyfed-Powys Police has not been linked to that campaign, the two incidents in close succession underscore that UK law enforcement organizations, and the personal data of their staff, have become a recurring target.

Impact Assessment

Impact AreaDescription
Operational DisruptionNon-emergency systems, including email and online contact channels, were taken offline or disrupted; 999 emergency response was not affected
Staff Privacy ExposurePotential compromise of officer and employee personal information remains under active investigation
Public Data ExposureNo evidence found to date that public/citizen personal data was accessed
Targeted Phishing RiskSecurity researchers warn that stolen staff details could be used to craft convincing phishing or social-engineering campaigns against police employees
Sector-Wide TrendFollows the ExfilSquad-claimed PNLD breach affecting more than 100,000 police and justice professionals a month earlier, suggesting sustained targeting of UK policing
Regulatory ExposureICO notification signals the incident is being treated as a potential personal-data breach under UK data protection law
Reputational/Trust ImpactDelayed public disclosure (roughly 11 days after detection) may draw scrutiny over transparency timelines

Recommendations

For Dyfed-Powys Police and Similar Forces

  • Complete and publish, where legally appropriate, a clear account of the affected systems, root cause, and specific staff data categories involved once the investigation concludes, to support affected employees in taking protective action.
  • Offer credit monitoring, identity-theft protection, or equivalent support to any staff confirmed to be affected, given the elevated targeting risk that comes with a law-enforcement staff roster.
  • Review and, if necessary, segment non-emergency IT systems (email, web contact forms, case-management back office) from emergency call-handling infrastructure to preserve the resilience demonstrated here, where 999 services stayed online throughout.
  • Coordinate with Tarian, the National Cyber Security Centre (NCSC), and the ICO to ensure consistent, timely public communication as findings develop.

For Security Teams at Other Public-Sector Organizations

  • Treat any breach affecting police or justice-sector staff rosters as a precursor risk: assume attackers may attempt to leverage exposed names, roles, and contact details for follow-on phishing or impersonation against officers, their families, or partner agencies.
  • Review email and web-facing contact systems for indicators of compromise consistent with initial-access techniques seen in recent UK public-sector intrusions, even absent a confirmed link to this specific incident.
  • Ensure incident-response plans include a clear internal/external data-classification split (public data vs. staff/employee data) so containment and disclosure decisions can be made quickly and communicated precisely, as Dyfed-Powys Police has done here.

For Affected Staff and Officers

  • Treat unexpected emails, texts, or calls referencing employer, payroll, or HR matters with heightened suspicion until the force confirms the scope of any staff data exposure.
  • Enable multi-factor authentication on personal accounts that share an email address or password with work accounts, and change any reused credentials as a precaution.
  • Monitor for signs of identity theft or targeted phishing attempts and report suspicious contact to force IT security and, where relevant, to Action Fraud.

Key Takeaways

  1. Dyfed-Powys Police disclosed on September 25, 2026 that a cyberattack detected on September 14, 2026 disrupted non-emergency systems and may have compromised staff data.
  2. Emergency 999 call-handling remained fully operational throughout; email and online contact channels were the systems disrupted.
  3. The force found no evidence that public/citizen personal data was accessed, but staff data exposure remains under active investigation.
  4. Tarian's cyber-crime unit is leading the technical investigation with outside cybersecurity specialist support, and the ICO has been notified.
  5. No group has claimed responsibility, and the force has not disclosed the attack's initial access method or technique.
  6. The incident follows the ExfilSquad-claimed breach of the UK Police National Legal Database roughly a month earlier, reinforcing a broader pattern of threat actors targeting UK policing and law-enforcement staff data.

Sources