Dyfed-Powys Police confirms cyber attack as staff information may have been compromised
Dyfed-Powys Police has confirmed that a cyber attack identified on 14 September disrupted non-emergency systems and may have exposed staff information. The force says it has found no evidence that public data was accessed.

Why it matters
What this means for organisations holding critical data
Dyfed-Powys Police has confirmed that a cyber attack identified on 14 September disrupted non-emergency systems and may have exposed staff information. The force says it has found no evidence that public data was accessed.
What happened
Dyfed-Powys Police has confirmed that it suffered a cyber attack, identified on 14 September 2026, which disrupted some of its non-emergency systems, according to Sky News and BBC News.
Online and email contact with the force was unavailable for a period after the incident. At the time, the force described the problem publicly only as "technical difficulties", as The Pembrokeshire Herald reported on 15 September. Those services have now been restored. The force says 999 and 101 were not affected and that it remained fully operational throughout.
The force says it is receiving support from cyber security specialists, that its systems have been subject to "precautionary measures" while the investigation continues, and that the Information Commissioner's Office (ICO) has been notified.
What the force has said about data
A spokesperson said: "At this stage, our investigation has found no evidence that members of the public's personal data has been accessed or compromised as a result of this incident."
The force added: "We are, however, continuing to investigate whether any information relating to our staff may have been accessed or compromised, and are taking all appropriate steps to protect that information, and will provide appropriate advice to colleagues if required."
What is not yet known
The force has not said who was responsible, how the attackers gained access, whether ransomware was involved or whether any demand has been made. No group has been publicly confirmed as responsible. It is also not yet known which categories of staff information, if any, were taken. Firevault will not speculate beyond what the force has confirmed.
Why this matters
Dyfed-Powys is the largest police force in England and Wales by area, covering Carmarthenshire, Ceredigion, Pembrokeshire and Powys and serving more than 500,000 residents, as LBC noted. Police staff information is not ordinary personnel data. Names, roles, home addresses and contact details of officers and staff can create personal safety risks, not just privacy risks.
The incident follows a pattern seen across UK public services: emergency functions are protected and stay up, while the connected back-office estate that holds staff, case and administrative records becomes the exposure point.
The Firevault view
The service can stay online. The retained data does not have to.
Keeping 999 and 101 running is the right priority, and the force deserves credit for that. The harder question for every police force, council and public body is which records need to be permanently reachable from the same network that attackers are probing, and which do not.
Historic HR files, vetting records, archived case material and older administrative data are rarely needed day to day. Holding those records in Offline Secure Storage®, physically disconnected until an authorised person needs them, means an intrusion into the live network cannot reach them. It also gives the organisation a clean, untouched copy to recover from if live systems are encrypted or altered.
What public bodies should do now
- Identify which staff and case records are held on connected systems and how long they have been retained.
- Separate records that must be live from those that only need to be kept.
- Move retained, rarely accessed records to physically offline storage with controlled, logged access.
- Test recovery from an offline copy, not only from connected backups.
- Plan staff communications in advance, including practical personal safety advice where officer details may be exposed.
How Firevault would handle this
A recovery copy an attacker cannot reach
Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.






