Skip to content

Security2 publishers2 min readPublished

Dyfed-Powys Police restores online contact as it checks whether attackers reached staff data

Dyfed-Powys Police says a cyberattack identified on September 14 may have exposed staff data at a force of more than 2,000 officers and staff. Online and email contact is back in service while investigators establish whether the attackers reached any staff records.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Dyfed-Powys Police restores online contact as it checks whether attackers reached staff data
Photo: yahoo.com

What happened

  • The attack disrupted only non-emergency systems, and the 999 and 101 telephone lines stayed up throughout.
  • The force says it has found no evidence that personal data belonging to members of the public was accessed.
  • Tarian, the regional organized crime unit for southern Wales, is leading the investigation with outside cybersecurity specialists.
  • The Information Commissioner's Office has been notified of the incident while the investigation continues.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Staff have to settle on their own precautions for now, because the force has committed to advising employees only 'if required'.
  • constraint Other police forces and public bodies have no indicator from this incident to check their own networks against until an entry point is published.
  • exposure Until the scope is set, any of the force's more than 2,000 officers and staff could be among those whose details were reached.

The staff-data inquiry is the job still running. Investigators are examining whether information relating to police staff was exposed, and the force says the full impact of the incident has not yet been established [6][7]. It has not said which staff records are involved, how the attackers got in, or who they are [7][11].

The force's statement led with the outage. "We can confirm that the force has been subject to a cyber incident which was identified on Monday September 14, 2026. The incident caused disruption to some non-emergency systems," it said [14]. Precautionary measures are now in place across its systems. Specialist teams are monitoring those systems while they investigate and restore services [16]. "We understand the potential concern this may cause," a spokesperson told The Record [15].

Restoring contact channels and scoping a data exposure are measured differently. The first is finished when the public can email the force again. The second is finished when investigators can say what the intruders touched, and the force says it has not reached that point [7]. Until it does, the risk to staff cannot be rated. On the force's account, the risk to the public is low [5].

One detail in the reporting did not come from the force: The Record's note that no group had claimed responsibility when it published [12]. Every other detail comes from the force and its spokesperson [14][15]. On that evidence this is one incident at one force.

What to watch

  • Dyfed-Powys Police naming the categories of staff data involved and issuing advice to employees.
  • A claim of responsibility or a leak-site listing that names the force.
  • The force or Tarian disclosing how the attackers got in.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories