Summary
- Dyfed-Powys Police says the incident identified on 14 September disrupted some non-emergency systems.
- Emergency response, 999 and 101 telephone services remained available, while temporarily disrupted online and email contact has been restored.
- The force has found no evidence that public personal data was accessed but is investigating possible exposure of staff information.
Dyfed-Powys Police is investigating whether staff information was accessed during a cyber incident that disrupted some of the force’s non-emergency systems.
Dyfed-Powys Police said the incident was identified on 14 September and triggered precautionary measures while specialist teams investigated and restored affected services.
The force remained operational throughout the disruption. Its emergency response was not affected, and 999 and 101 telephone services continued to function. Online and email contact were unavailable for a period but have since been restored.
In its 25 September statement, the force said investigators had found no evidence that personal information belonging to members of the public had been accessed or compromised.
It is continuing to investigate whether information relating to staff may have been accessed or compromised. The Information Commissioner’s Office has been notified.
The investigation is being managed by Tarian through its regional cybercrime unit, according to the force. Dyfed-Powys Police has not disclosed the initial attack vector, attributed the incident to a threat actor, or said whether ransomware, credential theft, exploitation of a vulnerability, or another technique was involved.
Those unknowns limit conclusions about the cause, but the operational pattern is clearer. The incident affected parts of the force’s digital environment sufficiently to interrupt email and online contact while leaving emergency communications available.
That separation is significant to resilience because critical public-safety functions do not necessarily share all of the dependencies of administrative and communications systems. An attack can still create substantial investigation, restoration, and data-protection work without preventing emergency calls from being handled.
Police organisations also hold information with widely differing sensitivity. Public records, investigative material, intelligence, employee information, credentials, and operational documentation create different consequences if accessed.
The force’s distinction between public and staff information therefore remains important while forensic work continues. Staff data can create privacy and security concerns in a law-enforcement environment, but Dyfed-Powys Police has not confirmed that such access occurred.
The incident sits within a wider resilience problem across UK public services, where organisations must maintain essential functions while investigating events that may affect interconnected systems, suppliers, and large stores of sensitive information.
Regulatory obligations also continue in parallel with technical recovery. Where personal information may have been exposed, organisations have to establish the categories of information involved, the affected population, the potential consequences, and whether further regulatory or individual notifications are required.
The force has already notified the ICO. Notification does not by itself establish that a reportable personal-data breach has been confirmed, particularly where forensic investigation into possible access is still under way.
Dyfed-Powys Police said it would provide further information when possible. The confirmed position remains disruption to some non-emergency systems, temporary loss of online and email contact, and an unresolved investigation into whether staff information was accessed.





