Tech
EN AZ
Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors

Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors

theguardian.com 18.09.2026 19:00 2 views
Exclusive: Official UK security assessment found Microsoft cloud platform storing files was at potential risk from hostile hackersVast troves of highly sensitive police data are lying on Microsoft cloud platforms which a

Vast troves of highly sensitive police data are lying on Microsoft cloud platforms which an official UK security assessment deemed to be vulnerable to “compromise” by foreign actors and the US government, a Guardian investigation can reveal. The files include criminal records, victim statements, internal emails and sensitive information held by more than 40 police forces across the UK. Some files exceed “official” classification, according to a police document seen by the Guardian, raising the possibility the information could be classed as “secret” or “top secret”.

The cloud platform is Microsoft Azure, one of the main commercial offerings of the US tech company. It is used by businesses and governments globally and rests on a web of IT infrastructure – datacentres, networking gear, fibre optic cables – that spans more than 100 countries. In recent years, doubts have surfaced about how cloud platforms store data and whether they are truly secure.

British police decided to put some of their most sensitive data on the Microsoft platform in a 2017 meeting, a record of which was examined by the Guardian. In doing so, officers accepted that “US government insiders” would be able to see the data, and that it could be “transmitted worldwide”, with “the extent of this … unknown”. According to five specialists who reviewed the Guardian’s findings, the risks identified in that document persist today.

Almost every UK police force now depends on Microsoft Azure, and the UK government spends at least £1.9bn on Microsoft software each year. The data is “some of the most sensitive that exists”, he added. These statements appeared to contradict public admissions by Microsoft, which said in a disclosure to Police Scotland in 2023 that data “can go outside the UK” and that it “cannot guarantee data sovereignty”.

Microsoft said it “does not provide any government with direct or unfettered access to customer data”, and that it had not provided UK data in response to a US government request. It added that, like all US-based tech companies, it responded to US government requests made through valid legal processes. In 2017, a senior police officer, Ian Dyson, chaired a meeting in which stakeholders considered 15 risks the UK would face if police forces decided to transfer their data to Microsoft’s global cloud.

That meeting considered both the police’s use of Microsoft’s software, such as Office 365, and the reliance on the cloud that underpins these services, Azure. Those risks, and the resulting police decisions, were set out in a summary document seen by the Guardian and signed off by Dyson. This was four years after the advent of a policy called “cloud first”.

Extract — continue reading at the source.

Read full story