Police staff data feared stolen in Welsh cyber raid
Officers warned: you're next.

- Dyfed-Powys Police is investigating whether staff information was exposed in a cyberattack.
- Emergency phone services stayed operational, but email and online contact services were temporarily unavailable.
- Experts warned stolen staff data could help attackers target police employees with convincing phishing messages.
- Police said they found no evidence that members of the public had their personal data compromised.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A cyberattack on a Welsh police force may have compromised staff information, prompting warnings that officers and other workers could now become targets
Dyfed-Powys Police said the cyber incident was detected on September 14th and caused disruption to some non-emergency systems.
Email and online contact services were temporarily unavailable but have since been restored.
In a statement shared on Friday, Dyfed-Powys Police said emergency services remained operational throughout the incident, with neither 999 nor 101 telephone services affected.
The force added that it had found no evidence that members of the public had their personal data accessed or compromised.
However, investigators are still trying to establish whether information relating to police staff was exposed.
Our systems have been subject to precautionary measures while specialist teams investigate the incident and work to restore services safely,– says Dyfed-Powys Police in a statement issued Friday.
The Information Commissioner’s Office (ICO) has been notified while the investigation is being managed by Tarian through its regional cybercrime unit.
Cyber security experts warned that the danger may not end with the breach as Trevor Dearing, senior director of Critical Infrastructure at Illumio, said.
“The concern right now has to be finding out whether staff data was compromised. Information about police officers and staff is highly sensitive and could be used to target individuals or to launch convincing phishing attacks against the force and its partners.
Jonathan Lee, cyber strategy director at Trend Micro warned police employees to be cautious of unexpected emails, text messages or phone calls designed to create a sense of urgency or persuade them to share sensitive information.
Dyfed-Powys Police serves more than 500,000 people across the rural heartlands of Carmarthenshire, Ceredigion, Pembrokeshire and Powys.
Earlier police database breach exposed 100,000 staff
The breach follows news last month that attackers exposed the contact details of more than 100,000 police officers and criminal justice professionals across England and Wales.
The data breach hit the UK Police National Legal Database (PNLD), an online legal reference service that has supported police forces for over three decades.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Staff detected the intrusion on Sunday, 26 July 2026. A data extortion group calling itself ExfilSquad – a relatively new kid on the block – later claimed responsibility for the attack and began demanding payment.
ExfilSquad alleges it took 1.9 GB of material covering roughly 135,000 records, split between about 114,000 PNLD subscribers and around 21,000 "Ask the Police" users.
The group also claimed a separate attack on American semiconductor firm Analog Devices and the UK Department of Education days earlier.