Drooid Logo
Back to story perspectives

Full Breakdown

Dyfed-Powys Police Cyber Incident Disrupts Non-Emergency Services

By Drooid · · How we work

Core Event

On September 14, Dyfed-Powys Police in Wales detected a cyber incident that compromised several non-emergency digital systems. Online and email contact channels were temporarily unavailable, although emergency call handling (999 and 101) continued without interruption. The force immediately engaged cyber-security specialists and activated precautionary measures while an investigation began.

Background & Context

The attack follows a July-2024 intrusion of the Police National Legal Database, a nationwide legal reference service used by all Home Office forces in England and Wales. That earlier breach exposed names, organisations and work email addresses of police officers and members of the public who had submitted queries via the “Ask the Police” portal. The recurrence highlights ongoing vulnerabilities in UK law-enforcement IT infrastructure.

Timeline

  • September 14 – The cyber incident is identified; Dyfed-Powys Police launch an investigation and notify the Information Commissioner’s Office (Information Commissioner's Office (ICO)).
  • September 25 – The force issues a public statement confirming no evidence that members of the public had their personal data accessed and reiterating that the investigation into possible staff data exposure continues.

Data & Statistics

  • The force serves Carmarthenshire, Ceredigion, Pembrokeshire and Powys, covering a population of more than 500,000 people, a figure that rises with tourism each year.
  • Emergency telephone services (999 and 101) remained fully operational throughout the incident.
  • Online and email contact services experienced a temporary outage; both have since been restored.
  • No public-facing personal data has been confirmed as accessed or compromised.

Official Statements & Responses

Dyfed-Powys Police indicated that the incident did not affect emergency response capabilities and that specialist cyber teams, supported by the regional organised-crime unit Tarian, are monitoring systems closely. The Information Commissioner’s Office confirmed receipt of the breach report and is assessing the information provided.

Conflicting Reports & Gaps

While the police and ICO agree that public data appears untouched, the investigation into staff data remains unresolved; no definitive conclusion has been reached about whether employee information was accessed. Additionally, the identity of the attackers and the method of entry have not been disclosed, leaving a critical gap in understanding the full scope of the breach.

Verbatim Quotes

  • “At this stage, our investigation has found no evidence that members of the public's personal data has been accessed or compromised as a result of this incident.” — Powys Police spokesperson
  • “We can confirm we have received a breach report from Dyfed-Powys Police and we are assessing the information provided.” — Dyfed-Powys Police
  • “A spokesperson said: "Dyfed Powys Police remains fully operational, and our response to emergency incidents has not been affected.” — Powys Police spokesperson
  • “The spokesperson added: "We understand the potential concern this may cause and want to reassure the public that we have and will continue to take all necessary steps to protect our information and maintain the security of our systems.” — The spokesperson