CSIDB logo
Incident

Dyfed-Powys Police

Incident posture

Attack window
Sep 2026
Location
United Kingdom
Status
Resolved
CIA posture
Available to members
Updated
2026-09-26 02:03

Linked entities

Victim
Dyfed-Powys Police
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Sep 2026
Disclosed
Sep 2026
Resolved
Sep 2026

Summary

Dyfed-Powys Police experienced a cyberattack that disrupted non-emergency systems while emergency services remained operational. The force reported that online and email contact channels were temporarily unavailable before being restored, and it is investigating whether staff data may have been accessed, with no evidence of public data compromise so far. The force is working with the Tarian regional cybercrime unit, external specialists, and has notified the Information Commissioner’s Office, and no ransomware group has claimed responsibility.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Dyfed-Powys Police identified the cyberattack on September 14 2026 and confirmed the incident publicly on September 25 2026, eleven days after initial detection. The force reported that the intrusion disrupted some non‑emergency systems, causing online and email contact channels for the public to be temporarily unavailable before being restored. Throughout the incident the emergency telephone lines, including the 999 number for immediate emergencies and the 101 number for non‑emergency reporting, remained operational. The force has not released a detailed hour‑by‑hour timeline of the attack and has not disclosed how the intrusion was first detected, whether through internal monitoring, an external tip or another method. No specific data fields have been named publicly, so it is not yet confirmed whether any exposure would involve names, contact details, payroll information or internal directories. The force drew a clear distinction between data belonging to members of the public and data belonging to its own staff, stating that its investigation had found no evidence that public personal data had been accessed or compromised.

The force notified the Information Commissioner’s Office as required by UK data‑protection law when personal data may be at risk, and it is working with Tarian, the regional organised crime and cybercrime unit for Wales, alongside external cybersecurity specialists to scope and remediate the intrusion. Dyfed‑Powys Police has not confirmed whether ransomware was involved in the attack and no ransomware group or named threat actor has claimed responsibility for the incident as of the public disclosure. The force’s spokesperson told the BBC that, at that stage, the investigation had found no evidence that members of the public’s personal data had been accessed or compromised as a result of the incident. Regarding staff data, the same spokesperson said the force was continuing to investigate whether any information relating to staff may have been accessed or compromised and was taking all appropriate steps to protect that information, adding that it would provide appropriate advice to colleagues if required. A further statement reported by The Register emphasized the force’s commitment to protect its information and maintain system security while acknowledging public concern. The force has not disclosed the scale of any potential staff‑data exposure, nor has it provided a definitive conclusion on whether staff data was actually compromised. As of the announcement, the investigation remained ongoing and no further technical details about the attacker’s methods, tools or motives had been made public.

Sources

Sources available to members: 1 source.

CSIDB