Dyfed-Powys Police is investigating a cyberattack that disrupted some of its non-emergency systems, with specialist cybercrime officers examining whether information relating to staff may have been accessed or compromised.
Dyfed-Powys Police is investigating a cyberattack that caused disruption to some of its non-emergency systems.
The force said the incident was identified on September 14 and resulted in disruption to some non-emergency systems.
Emergency and frontline policing services were not affected by the incident and the force said its online and email services have since been restored.
An investigation is underway involving specialist cybercrime officers, with the force working to establish the circumstances surrounding the incident and the potential impact on its data.
Dyfed-Powys Police said there is currently no evidence that personal information belonging to members of the public has been accessed or compromised.
However, investigations are continuing to determine whether information relating to police staff may have been affected.
The force said: “At this stage, there is no evidence that members of the public’s personal data has been accessed or compromised.”
It added that it was continuing to assess whether any information relating to staff had been accessed or compromised as part of the incident.
Dyfed-Powys Police said its investigation remains ongoing and further updates will be provided when appropriate.
Graeme Stewart, Head Of Public Sector at Check Point, said: “The biggest mistake would be to look at this and think the danger is limited because public data does not appear to have been accessed. Police staff data can be hugely valuable to an attacker. Names, roles, contact details and internal information can all be used to build convincing phishing attacks, impersonate colleagues and target people with access to more sensitive systems. That means the risk does not end when the systems come back online.
“If information has been taken, it can be weaponised weeks or months later. The disruption to non-emergency systems also tells us this was not trivial. Investigators now need to understand how the attackers got in, how far they moved through the network and exactly what they were able to access. You do not need to take down 999 to cause serious damage to a police force. Sometimes knowing who works there, what they do and how the organisation operates is valuable enough.”
James Neilson, SVP Of Global at OPSWAT, said: “It’s a relief that disruption at Dyfed-Powys Police appears limited to online and email contact services. When attacks hit emergency services, the impact can be serious. Police forces are already under considerable pressure and avoiding that kind of operational downtime matters.
“A key next step will be establishing whether any staff personal information has been accessed. Officers working on serious organised and major crime will understandably want reassurance about what, if anything, has been exposed.
“During any cyberattack, the priorities are keeping critical services running and protecting sensitive data. Time is the most valuable resource in incident response, so fast detection, response and recovery are essential.
“This is a challenge for the whole public sector, where legacy systems and fragmented oversight often leave organisations without the resources they need against evolving threats. Secure file transfer, combined with file inspection and malware scanning, can help stop malicious payloads reaching critical systems through trusted data exchanges.”
Trevor Dearing, Senior Director Of Critical Infrastructure at Illumio, said: “The disruption to online and email contact services, and the questions over whether staff information was accessed, are still a huge problem.
“The concern right now has to be finding out whether staff data was compromised. Information about police officers and staff is highly sensitive and could be used to target individuals or to launch convincing phishing attacks against the force and its partners.
“This is the latest in a long line of attacks on public sector organisations this year. After so many warnings, too many organisations still focus on keeping attackers out rather than limiting what they can reach once inside. Forces need to build their defences around containment, so an intruder can’t move freely from a non-emergency system to sensitive staff records.”

