Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised

Cyberattack Disrupts Dyfed-Powys Police Systems in Wales (TL-2026-2694) is a medium-severity data breach, first published 2026-09-25. It has no confirmed attribution, affects Dyfed-Powys Police Internal non-emergency IT systems (public, maps to 8 MITRE ATT&CK techniques (T1005, T1021, T1078), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-2694

Threat ID
TL-2026-2694
Severity
MEDIUM
Status
ACTIVE
Category
DATA_BREACH
First published
2026-09-25
Last reviewed
2026-09-25
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, police - law enforcement, public sector
Target regions
Wales, united kingdom
Detection rules
9
Indicators of compromise
18

Malware and tooling in Cyberattack Disrupts Dyfed-Powys Police Systems in Wales

Malware and tooling: ExfilSquad

Dyfed-Powys Police, a Welsh regional force covering southwest and mid Wales with over 2,000 officers and staff, disclosed on September 25, 2026 that a cyberattack identified on September 14, 2026 disrupted non-emergency IT systems including email and online public-contact services. No evidence of public data compromise has been found, but investigation into possible staff/employee data compromise continues, with no group claiming responsibility.

How Cyberattack Disrupts Dyfed-Powys Police Systems in Wales works

On September 25, 2026, Dyfed-Powys Police confirmed it had suffered a cyberattack that was first identified on Monday, September 14, 2026 -- an 11-day gap between detection and public disclosure. Per shattered.io's reporting, the intrusion was flagged internally after the force noticed "unusual activity" on its network that day. The attack disrupted some of the force's non-emergency IT systems -- multiple outlets describe the affected estate as the online public-contact channel, email services, and, per shattered.io, wider "back-office systems" -- all of which were temporarily unavailable and have since been restored. Critically, the force's 999 and 101 emergency call-handling capability remained fully operational throughout, and Dyfed-Powys Police stated it remains fully operational as a force.

The force has found no evidence that personal data belonging to members of the public was accessed or compromised. However, it is still investigating whether information relating to its own staff and employees was accessed or compromised, and has stated it is taking precautionary steps to protect that information and will advise affected colleagues if necessary. The Information Commissioner's Office (ICO) has been notified of the potential personal data breach, consistent with UK GDPR reporting obligations for police data controllers.

The investigation is being led by Tarian, the regional organised crime unit for southern Wales, operating through its cyber-crime unit and supported by external cybersecurity specialists. As of the most recent coverage reviewed (checked through September 27, 2026, across fourteen primary news outlets/trackers -- including The Record, The Register, Cambrian News, Swansea Bay News, BritBrief, Daily Post (x2), GB News, Yahoo News UK, tech-insider.org, Mallory, jointheclaim.com, shattered.io, UKAuthority, and Shropshire Star -- plus independent follow-up analyses), no threat actor or extortion group has claimed responsibility, no ransomware has been confirmed or ruled out, no CVE or specific vulnerability has been disclosed, and the initial access vector has not been made public. jointheclaim.com states explicitly: "Dyfed-Powys Police has not said who carried out the attack, how the attackers gained initial access, whether ransomware was involved, or what data, if any, was actually taken." Dyfed-Powys Police has characterized the response measures taken as "precautionary" while systems are monitored and services are restored.

A note on a sourcing pitfall specifically checked and ruled out during this research pass: automated web-search summarization surfaced a claim that the data-extortion group ExfilSquad "claimed responsibility" for this attack. On verification against primary reporting, this is a conflation with the separate, unrelated Police National Legal Database (PNLD) breach -- ExfilSquad's claimed intrusion there was detected 26 July 2026, three-plus months before Dyfed-Powys Police's 14 September 2026 detection date, and no primary source reviewed (including jointheclaim.com and shattered.io, both of which discuss the incident's unresolved attribution directly) ties ExfilSquad, or any other named actor, to the Dyfed-Powys Police attack. That non-attribution is treated as confirmed fact here, not as an open question.

Because of this evidentiary gap, the MITRE ATT&CK mapping below is deliberately bounded to only the tactics/techniques necessarily implied by the confirmed, disclosed effects -- disruption of named non-emergency IT services (email; online public-contact portal; back-office systems) reached via some undisclosed initial foothold, and a possible, still-unconfirmed compromise of internally held staff records -- rather than a confirmed exploit chain. Discovery techniques are inferred because an intruder would need to enumerate accounts, files/directories, and system context to distinguish and reach these specific non-emergency systems while emergency (999/101) infrastructure stayed unaffected, consistent with network/system segmentation. Collection techniques are inferred from the disclosed scope of the still-open staff-data investigation, including email specifically, since email service was named among the affected systems. A Lateral Movement technique (Remote Services) is likewise inferred as necessarily implied: three distinct internal system categories -- online public-contact portal, email, and wider back-office systems -- were all disrupted while the separately hosted 999/101 emergency call-handling estate stayed unaffected, which requires the intruder to have moved from a single initial foothold across multiple internal hosts/services rather than having gained parallel direct access to each; no specific lateral-movement protocol or tool has been disclosed, so only the base technique is carried, not a sub-technique. Two Impact techniques are listed side-by-side (Service Stop and Endpoint Denial of Service) because the single confirmed technical fact -- named systems went offline for a period and were later restored -- is consistent with either an adversary directly halting/disabling services or a resource-exhaustion/DoS effect, and no source disambiguates which occurred; both are carried as alternative hypotheses for the same observed effect rather than a confirmed technique. No vector, malware family, or actor from any comparable contemporaneous incident (see below) has been linked to this attack by any source reviewed, and none is asserted here. This should be treated as a developing story; attribution, vector, and final data-impact scope may be revised as Tarian's investigation concludes.

This incident sits within a run of UK policing-sector data-protection events cited as sector context by multiple outlets covering the story, none of which has been linked to the Dyfed-Powys Police cyberattack by any source: (1) a September 2023 ransomware attack on ID-card supplier Digital ID that exposed personal data of over 12,500 Greater Manchester Police officers and staff; (2) an August 2026 ICO enforcement notice and reprimand against the Metropolitan Police Service for unrelated data-handling failures (unredacted case documents and a misaddressed email exposing case-related identities); and (3) a July-August 2026 breach of the Police National Legal Database (PNLD) -- the shared legal-reference service used for three decades by all 43 Home Office police forces in England and Wales plus the British Transport Police. The PNLD incident was discovered on July 26, 2026 and publicly confirmed on August 3, 2026: the data-extortion group ExfilSquad claimed responsibility, alleging theft of roughly 1.9GB / ~135,000 records (about 114,000 PNLD subscriber records covering police officers, police staff, criminal-justice professionals and government partners, plus roughly 21,000 email addresses of public "Ask the Police" website users), published on ExfilSquad's dark-web leak site with a sample and a ransom demand; PNLD stated no ransom was paid and found no evidence that passwords or other login credentials were accessed. The PNLD breach was investigated by the National Crime Agency, the North East Regional Organised Crime Unit, and external cybersecurity specialists, with the ICO also notified. Researchers and reporting tied ExfilSquad's access to misconfigured Microsoft Power Pages portals exposing underlying Microsoft Dynamics 365 / Dataverse data (not a Dynamics 365 product vulnerability), and the same group claimed contemporaneous July-August 2026 breaches of the UK Department for Education (600,000+ records claimed), the Ministry of Defence, and the Home Office. No source reviewed connects ExfilSquad, a Power Platform misconfiguration, or any of these other victims to the Dyfed-Powys Police cyberattack; they are documented here strictly as comparative UK public-sector cyber-risk context.

MITRE ATT&CK techniques used in TL-2026-2694

Collection

T1005 Data from Local System; T1114 Email Collection; T1213 Data from Information Repositories

Lateral Movement

T1021 Remote Services

Initial Access

T1078 Valid Accounts

Discovery

T1082 System Information Discovery; T1087 Account Discovery

Impact

T1489 Service Stop

Affected products and versions in Cyberattack Disrupts Dyfed-Powys Police Systems in Wales

  • Dyfed-Powys Police — Internal non-emergency IT systems (public online-contact portal, email services, and back-office systems)
    Vulnerable versions: Affected as of detection on 14 September 2026; specific software/versions not disclosed
    Fixed in: Services confirmed restored to normal operation by public disclosure on 25 September 2026

Remediation for Cyberattack Disrupts Dyfed-Powys Police Systems in Wales

Patches

  • No CVE or specific software vulnerability has been publicly disclosed for this incident; vendor patching guidance is not applicable pending the outcome of Tarian's forensic investigation.

Immediate actions

  • Advise all Dyfed-Powys Police staff to treat unsolicited emails, calls, or messages referencing the incident as potential phishing or social-engineering attempts, given the possible exposure of employee contact details.
  • Reset credentials and review access/authentication logs for accounts tied to the affected email, online-contact, and back-office systems as a precaution while the scope of any unauthorized access is confirmed.
  • Continue routing time-critical public contact through the confirmed-unaffected 999/101 emergency channels while non-emergency online and email contact systems remain under close monitoring following restoration.

Workarounds

  • Maintain alternate/manual intake channels for non-emergency public contact in the event online contact or email systems are again taken offline during remediation.

Longer-term hardening

  • Enforce phishing-resistant multi-factor authentication and periodic privileged-access reviews across internal and internet-facing police force IT systems to reduce the risk of credential-based initial access.
  • Apply stronger data-minimization and access segmentation to internal HR/personnel record repositories and email systems, informed by comparable UK policing-sector incidents such as the 2023 Greater Manchester Police / Digital ID supplier breach and the 2026 PNLD / ExfilSquad breach.
  • Audit any Microsoft Power Platform (Power Pages/Power Apps) portals and their underlying Dataverse/Dynamics 365 data stores for anonymous-access misconfigurations, given the confirmed exploitation of this pattern against another UK public-sector body (PNLD) in the same reporting period.
  • Review incident-detection-to-disclosure timelines against ICO and UK GDPR expectations to reduce the gap between initial detection and public/staff notification (11 days in this case).
  • Maintain network segmentation and monitoring that verifiably isolates emergency call-handling (999/101) infrastructure from back-office, email, and public-contact systems, and periodically validate that isolation under incident conditions.

Timeline of Cyberattack Disrupts Dyfed-Powys Police Systems in Wales

  • Sector context (unrelated to Dyfed-Powys): the Police National Legal Database (PNLD), used by all 43 Home Office police forces in England and Wales plus British Transport Police, discovers a separate security incident later claimed by the data-extortion group ExfilSquad.
  • Sector context (unrelated to Dyfed-Powys): PNLD publicly confirms data theft after ExfilSquad publishes a sample of roughly 135,000 records on its dark-web leak site and demands a ransom; PNLD states no ransom was paid and no credentials were confirmed compromised.
  • Tarian, the regional organised crime unit for southern Wales, begins a forensic investigation through its cyber-crime unit, supported by external cybersecurity specialists.
  • The force places affected systems under precautionary protective measures and close monitoring while engaging cybersecurity specialists; 999 and 101 emergency call handling continues unaffected throughout.
  • Dyfed-Powys Police identifies a cyberattack after noticing unusual network activity, disrupting some non-emergency IT systems, including the force's online public-contact channel, email services, and wider back-office systems.
  • No threat actor or group has claimed responsibility for the attack as of the force's public statement.
  • Previously disrupted online and email contact services are confirmed restored to normal operation.
  • The Information Commissioner's Office (ICO) is confirmed to have been notified of the potential personal data breach involving staff information, consistent with UK GDPR reporting obligations.
  • Dyfed-Powys Police publicly confirms the cyberattack, 11 days after detection, stating there is no evidence that members of the public's personal data were accessed but that investigation into potential staff/employee data compromise is ongoing.
  • Follow-up reporting (jointheclaim.com) reiterates that Dyfed-Powys Police has not said who carried out the attack, how initial access was gained, whether ransomware was involved, or what data was actually taken.

Sources cited for Cyberattack Disrupts Dyfed-Powys Police Systems in Wales

More in data breach

Detection coverage for TL-2026-2694

As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2694 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats