Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised
Cyberattack Disrupts Dyfed-Powys Police Systems in Wales (TL-2026-2694) is a medium-severity data breach, first published 2026-09-25. It has no confirmed attribution, affects Dyfed-Powys Police Internal non-emergency IT systems (public, maps to 8 MITRE ATT&CK techniques (T1005, T1021, T1078), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-2694
- Threat ID
- TL-2026-2694
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-09-25
- Last reviewed
- 2026-09-25
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, police - law enforcement, public sector
- Target regions
- Wales, united kingdom
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Cyberattack Disrupts Dyfed-Powys Police Systems in Wales
Malware and tooling: ExfilSquad
Dyfed-Powys Police, a Welsh regional force covering southwest and mid Wales with over 2,000 officers and staff, disclosed on September 25, 2026 that a cyberattack identified on September 14, 2026 disrupted non-emergency IT systems including email and online public-contact services. No evidence of public data compromise has been found, but investigation into possible staff/employee data compromise continues, with no group claiming responsibility.
How Cyberattack Disrupts Dyfed-Powys Police Systems in Wales works
On September 25, 2026, Dyfed-Powys Police confirmed it had suffered a cyberattack that was first identified on Monday, September 14, 2026 -- an 11-day gap between detection and public disclosure. Per shattered.io's reporting, the intrusion was flagged internally after the force noticed "unusual activity" on its network that day. The attack disrupted some of the force's non-emergency IT systems -- multiple outlets describe the affected estate as the online public-contact channel, email services, and, per shattered.io, wider "back-office systems" -- all of which were temporarily unavailable and have since been restored. Critically, the force's 999 and 101 emergency call-handling capability remained fully operational throughout, and Dyfed-Powys Police stated it remains fully operational as a force.
The force has found no evidence that personal data belonging to members of the public was accessed or compromised. However, it is still investigating whether information relating to its own staff and employees was accessed or compromised, and has stated it is taking precautionary steps to protect that information and will advise affected colleagues if necessary. The Information Commissioner's Office (ICO) has been notified of the potential personal data breach, consistent with UK GDPR reporting obligations for police data controllers.
The investigation is being led by Tarian, the regional organised crime unit for southern Wales, operating through its cyber-crime unit and supported by external cybersecurity specialists. As of the most recent coverage reviewed (checked through September 27, 2026, across fourteen primary news outlets/trackers -- including The Record, The Register, Cambrian News, Swansea Bay News, BritBrief, Daily Post (x2), GB News, Yahoo News UK, tech-insider.org, Mallory, jointheclaim.com, shattered.io, UKAuthority, and Shropshire Star -- plus independent follow-up analyses), no threat actor or extortion group has claimed responsibility, no ransomware has been confirmed or ruled out, no CVE or specific vulnerability has been disclosed, and the initial access vector has not been made public. jointheclaim.com states explicitly: "Dyfed-Powys Police has not said who carried out the attack, how the attackers gained initial access, whether ransomware was involved, or what data, if any, was actually taken." Dyfed-Powys Police has characterized the response measures taken as "precautionary" while systems are monitored and services are restored.
A note on a sourcing pitfall specifically checked and ruled out during this research pass: automated web-search summarization surfaced a claim that the data-extortion group ExfilSquad "claimed responsibility" for this attack. On verification against primary reporting, this is a conflation with the separate, unrelated Police National Legal Database (PNLD) breach -- ExfilSquad's claimed intrusion there was detected 26 July 2026, three-plus months before Dyfed-Powys Police's 14 September 2026 detection date, and no primary source reviewed (including jointheclaim.com and shattered.io, both of which discuss the incident's unresolved attribution directly) ties ExfilSquad, or any other named actor, to the Dyfed-Powys Police attack. That non-attribution is treated as confirmed fact here, not as an open question.
Because of this evidentiary gap, the MITRE ATT&CK mapping below is deliberately bounded to only the tactics/techniques necessarily implied by the confirmed, disclosed effects -- disruption of named non-emergency IT services (email; online public-contact portal; back-office systems) reached via some undisclosed initial foothold, and a possible, still-unconfirmed compromise of internally held staff records -- rather than a confirmed exploit chain. Discovery techniques are inferred because an intruder would need to enumerate accounts, files/directories, and system context to distinguish and reach these specific non-emergency systems while emergency (999/101) infrastructure stayed unaffected, consistent with network/system segmentation. Collection techniques are inferred from the disclosed scope of the still-open staff-data investigation, including email specifically, since email service was named among the affected systems. A Lateral Movement technique (Remote Services) is likewise inferred as necessarily implied: three distinct internal system categories -- online public-contact portal, email, and wider back-office systems -- were all disrupted while the separately hosted 999/101 emergency call-handling estate stayed unaffected, which requires the intruder to have moved from a single initial foothold across multiple internal hosts/services rather than having gained parallel direct access to each; no specific lateral-movement protocol or tool has been disclosed, so only the base technique is carried, not a sub-technique. Two Impact techniques are listed side-by-side (Service Stop and Endpoint Denial of Service) because the single confirmed technical fact -- named systems went offline for a period and were later restored -- is consistent with either an adversary directly halting/disabling services or a resource-exhaustion/DoS effect, and no source disambiguates which occurred; both are carried as alternative hypotheses for the same observed effect rather than a confirmed technique. No vector, malware family, or actor from any comparable contemporaneous incident (see below) has been linked to this attack by any source reviewed, and none is asserted here. This should be treated as a developing story; attribution, vector, and final data-impact scope may be revised as Tarian's investigation concludes.
This incident sits within a run of UK policing-sector data-protection events cited as sector context by multiple outlets covering the story, none of which has been linked to the Dyfed-Powys Police cyberattack by any source: (1) a September 2023 ransomware attack on ID-card supplier Digital ID that exposed personal data of over 12,500 Greater Manchester Police officers and staff; (2) an August 2026 ICO enforcement notice and reprimand against the Metropolitan Police Service for unrelated data-handling failures (unredacted case documents and a misaddressed email exposing case-related identities); and (3) a July-August 2026 breach of the Police National Legal Database (PNLD) -- the shared legal-reference service used for three decades by all 43 Home Office police forces in England and Wales plus the British Transport Police. The PNLD incident was discovered on July 26, 2026 and publicly confirmed on August 3, 2026: the data-extortion group ExfilSquad claimed responsibility, alleging theft of roughly 1.9GB / ~135,000 records (about 114,000 PNLD subscriber records covering police officers, police staff, criminal-justice professionals and government partners, plus roughly 21,000 email addresses of public "Ask the Police" website users), published on ExfilSquad's dark-web leak site with a sample and a ransom demand; PNLD stated no ransom was paid and found no evidence that passwords or other login credentials were accessed. The PNLD breach was investigated by the National Crime Agency, the North East Regional Organised Crime Unit, and external cybersecurity specialists, with the ICO also notified. Researchers and reporting tied ExfilSquad's access to misconfigured Microsoft Power Pages portals exposing underlying Microsoft Dynamics 365 / Dataverse data (not a Dynamics 365 product vulnerability), and the same group claimed contemporaneous July-August 2026 breaches of the UK Department for Education (600,000+ records claimed), the Ministry of Defence, and the Home Office. No source reviewed connects ExfilSquad, a Power Platform misconfiguration, or any of these other victims to the Dyfed-Powys Police cyberattack; they are documented here strictly as comparative UK public-sector cyber-risk context.
MITRE ATT&CK techniques used in TL-2026-2694
Collection
T1005 Data from Local System; T1114 Email Collection; T1213 Data from Information Repositories
Lateral Movement
Initial Access
Discovery
T1082 System Information Discovery; T1087 Account Discovery
Impact
Affected products and versions in Cyberattack Disrupts Dyfed-Powys Police Systems in Wales
- Dyfed-Powys Police — Internal non-emergency IT systems (public online-contact portal, email services, and back-office systems)
Vulnerable versions: Affected as of detection on 14 September 2026; specific software/versions not disclosed
Fixed in: Services confirmed restored to normal operation by public disclosure on 25 September 2026
Remediation for Cyberattack Disrupts Dyfed-Powys Police Systems in Wales
Patches
- No CVE or specific software vulnerability has been publicly disclosed for this incident; vendor patching guidance is not applicable pending the outcome of Tarian's forensic investigation.
Immediate actions
- Advise all Dyfed-Powys Police staff to treat unsolicited emails, calls, or messages referencing the incident as potential phishing or social-engineering attempts, given the possible exposure of employee contact details.
- Reset credentials and review access/authentication logs for accounts tied to the affected email, online-contact, and back-office systems as a precaution while the scope of any unauthorized access is confirmed.
- Continue routing time-critical public contact through the confirmed-unaffected 999/101 emergency channels while non-emergency online and email contact systems remain under close monitoring following restoration.
Workarounds
- Maintain alternate/manual intake channels for non-emergency public contact in the event online contact or email systems are again taken offline during remediation.
Longer-term hardening
- Enforce phishing-resistant multi-factor authentication and periodic privileged-access reviews across internal and internet-facing police force IT systems to reduce the risk of credential-based initial access.
- Apply stronger data-minimization and access segmentation to internal HR/personnel record repositories and email systems, informed by comparable UK policing-sector incidents such as the 2023 Greater Manchester Police / Digital ID supplier breach and the 2026 PNLD / ExfilSquad breach.
- Audit any Microsoft Power Platform (Power Pages/Power Apps) portals and their underlying Dataverse/Dynamics 365 data stores for anonymous-access misconfigurations, given the confirmed exploitation of this pattern against another UK public-sector body (PNLD) in the same reporting period.
- Review incident-detection-to-disclosure timelines against ICO and UK GDPR expectations to reduce the gap between initial detection and public/staff notification (11 days in this case).
- Maintain network segmentation and monitoring that verifiably isolates emergency call-handling (999/101) infrastructure from back-office, email, and public-contact systems, and periodically validate that isolation under incident conditions.
Timeline of Cyberattack Disrupts Dyfed-Powys Police Systems in Wales
- Sector context (unrelated to Dyfed-Powys): the Police National Legal Database (PNLD), used by all 43 Home Office police forces in England and Wales plus British Transport Police, discovers a separate security incident later claimed by the data-extortion group ExfilSquad.
- Sector context (unrelated to Dyfed-Powys): PNLD publicly confirms data theft after ExfilSquad publishes a sample of roughly 135,000 records on its dark-web leak site and demands a ransom; PNLD states no ransom was paid and no credentials were confirmed compromised.
- Tarian, the regional organised crime unit for southern Wales, begins a forensic investigation through its cyber-crime unit, supported by external cybersecurity specialists.
- The force places affected systems under precautionary protective measures and close monitoring while engaging cybersecurity specialists; 999 and 101 emergency call handling continues unaffected throughout.
- Dyfed-Powys Police identifies a cyberattack after noticing unusual network activity, disrupting some non-emergency IT systems, including the force's online public-contact channel, email services, and wider back-office systems.
- No threat actor or group has claimed responsibility for the attack as of the force's public statement.
- Previously disrupted online and email contact services are confirmed restored to normal operation.
- The Information Commissioner's Office (ICO) is confirmed to have been notified of the potential personal data breach involving staff information, consistent with UK GDPR reporting obligations.
- Dyfed-Powys Police publicly confirms the cyberattack, 11 days after detection, stating there is no evidence that members of the public's personal data were accessed but that investigation into potential staff/employee data compromise is ongoing.
- Follow-up reporting (jointheclaim.com) reiterates that Dyfed-Powys Police has not said who carried out the attack, how initial access was gained, whether ransomware was involved, or what data was actually taken.
Sources cited for Cyberattack Disrupts Dyfed-Powys Police Systems in Wales
- Cyberattack hits Welsh police force, may have affected staff data
- Dyfed-Powys Police hit by cyber attack
- Cyber attack on Dyfed-Powys Police hit and the force still can't say whether staff data was accessed
- Dyfed-Powys Police confirms cyber incident, staff data may be compromised
- Welsh police force hit by cyber attack
- Cyber attack on Dyfed-Powys Police may have compromised staff data
- Dyfed-Powys: Welsh police force suffers major cyberattack which 'may have compromised staff data'
- Dyfed-Powys Police cops to cyberattack, staff data potentially nicked
- Cyber attack on Dyfed-Powys Police may have compromised staff data
- Welsh Police Cyberattack Hits Staff Data 11 Days On
- Cyberattack Disrupts Dyfed-Powys Police and May Expose Staff Data
- Dyfed-Powys Police cyber-attack: what we know about the potential staff data breach
- Dyfed-Powys Police Cyber Attack: 11-Day Staff Probe
- Dyfed-Powys Police cyber incident disrupts non-emergency systems
- Dyfed Powys Police confirms it has been hit by cyber attack as investigation under way
More in data breach
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour Extortion
- Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image Upload Server Exploit
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)
Detection coverage for TL-2026-2694
As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2694 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.