Summary
- Dyfed-Powys Police identified the incident on 14 September and says some non-emergency systems were disrupted.
- The force has found no evidence that members of the public had personal data compromised but continues investigating possible staff-data access.
- Emergency policing and 999 and 101 telephone services remained operational while recovery and forensic work continued.
Dyfed-Powys Police is investigating whether staff information was accessed during a cyber attack that disrupted some non-emergency systems, leaving the Welsh force restoring services while investigators continue establishing the scope of the intrusion.
The force identified the incident on 14 September. Emergency policing remained operational, while 999 and 101 telephone services were unaffected. Online and email contact were unavailable for a period but have since been restored.
Dyfed-Powys Police says it has found no evidence that personal information belonging to members of the public was accessed or compromised. It continues to investigate whether information relating to employees may have been affected.
The force has not disclosed how attackers gained access, what staff-data categories are being examined, or whether ransomware or extortion was involved. No public attribution has been made.
Recovery begins before every fact is known
Cyber incidents rarely unfold in a clean sequence where investigators establish exactly what happened before restoration starts. Systems may need to be isolated, credentials reset, suppliers contacted, and alternative processes introduced while forensic work is still under way.
That creates a tension between speed and evidence. Bringing technology back too quickly can reintroduce compromised systems or destroy useful forensic information, while leaving services offline prolongs disruption.
Police technology estates make the problem particularly demanding because administrative applications can sit alongside operational systems, communications, evidence platforms, staff records, national services, and third-party suppliers.
Dyfed-Powys Police has been clear that the affected services were non-emergency systems, so there is no basis to infer that operational policing databases or evidence systems were compromised.
Staff information can still create significant exposure
The absence of evidence that public information was affected narrows the immediate concern, but employee information can also be sensitive within policing organisations.
The force has not identified which categories of staff information may have been exposed, making it inappropriate to speculate about the sensitivity or extent of any compromise.
The uncertainty nevertheless illustrates why breach investigations can continue after services return. Logs from identity platforms, endpoints, applications, cloud services, and network systems have to be reconstructed to establish what an attacker could access and whether data was actually taken.
Public bodies also face an operational constraint that commercial organisations can sometimes avoid: they must continue providing essential services while their own technology environment is being examined.
Resilience is measured during recovery
The incident shows why cyber resilience extends beyond preventative controls. Organisations can invest in authentication, endpoint security, monitoring, and staff training while still requiring tested procedures for continuing to operate when part of the environment is unavailable.
Backups, alternative communications, identity recovery, supplier contacts, and clearly understood minimum services can determine how long disruption lasts after an attacker is contained.
The investigation into Dyfed-Powys Police is being managed by Tarian, the regional organised-crime unit for southern Wales, with cybersecurity specialists involved.
Further disclosure will determine whether the episode develops into a significant data breach or remains primarily an operational disruption. At present, the established facts are narrower: some non-emergency systems were affected, emergency services remained available, public data is not known to have been compromised, and possible staff-data access is still under investigation.












