Vast troves of highly sensitive police data are lying on Microsoft cloud platforms which an official UK security assessment deemed to be vulnerable to “compromise” by foreign actors and the US government, a Guardian investigation can reveal. This was reported by Qazaqyia.kz citing The Guardian.
The files include criminal records, victim statements, internal emails and sensitive information held by more than 40 police forces across the UK.
Some files exceed “official” classification, according to a police document seen by the Guardian, raising the possibility the information could be classed as “secret” or “top secret”.
The cloud platform is Microsoft Azure, one of the main commercial offerings of the US tech company. It is used by businesses and governments globally and rests on a web of IT infrastructure – datacentres, networking gear, fibre optic cables – that spans more than 100 countries.
In recent years, doubts have surfaced about how cloud platforms store data and whether they are truly secure.
British police decided to put some of their most sensitive data on the Microsoft platform in a 2017 meeting, a record of which was examined by the Guardian.
In doing so, officers accepted that “US government insiders” would be able to see the data, and that it could be “transmitted worldwide”, with “the extent of this … unknown”.
According to five specialists who reviewed the Guardian’s findings, the risks identified in that document persist today. Almost every UK police force now depends on Microsoft Azure, and the UK government spends at least £1.9bn on Microsoft software each year.
“There’s no evidence that this has been properly understood,” said one source who has held senior roles in UK policing. The data is “some of the most sensitive that exists”, he added. “You’re talking about information that, if it gets into the wrong hands, or if the information is incorrect, [means] people can get hurt or may die.”
When the Guardian approached the police about the possibility that sensitive information was not secure, they appeared to wave aside these risks, saying Britain’s contracts with Microsoft meant US authorities could not view data without express permission and that the data it stored on Microsoft remained in the UK.
These statements appeared to contradict public admissions by Microsoft, which said in a disclosure to Police Scotland in 2023 that data “can go outside the UK” and that it “cannot guarantee data sovereignty”.
Microsoft said it “does not provide any government with direct or unfettered access to customer data”, and that it had not provided UK data in response to a US government request. It added that, like all US-based tech companies, it responded to US government requests made through valid legal processes.
In 2017, a senior police officer, Ian Dyson, chaired a meeting in which stakeholders considered 15 risks the UK would face if police forces decided to transfer their data to Microsoft’s global cloud.
That meeting considered both the police’s use of Microsoft’s software, such as Office 365, and the reliance on the cloud that underpins these services, Azure. Those risks, and the resulting police decisions, were set out in a summary document seen by the Guardian and signed off by Dyson.
This was four years after the advent of a policy called “cloud first”. Introduced by the Cabinet Office in 2013, it became a government-wide effort to push almost all departments to migrate their data on to the “public cloud” – commercial offerings by tech companies, often based in the US. Departments that did not want to do this had to jump through burdensome administrative hoops.
Dyson was the police commissioner of the City of London at the time, but he held another title: senior information risk owner for all of Britain, or the SIRO. It was his job to set the norms for how British police could safely handle their data.
In their assessment, officers came to startling conclusions about what would happen if they put police data on Azure. Firstly, they considered it would be vulnerable to hackers: Microsoft’s software “carries vulnerabilities which will be exploited by cybercriminals and other threat actors in due course”.
Separately, it added: “Police forces cannot be certain where their data will be processed or stored.
“The hyper-scale and global nature of the Microsoft cloud means that police data, and metadata relating to police data could be transmitted and stored worldwide by Microsoft, and the extent of this will be unknown.”
The document specifically identified the potential risk from what it described as “US government insiders”. It said: “There is a risk of compromise of sensitive data shared by, or taken from, Microsoft by the US government being released by US government insider attackers.”
The document explained that the data intended for migration was sensitive. In fact, “a significant volume” of it exceeded the classification “official”. In the UK, this suggests it was either “official sensitive”, “secret”, or “top secret”.
The assessment also suggested Microsoft’s platform was unable to guarantee this data would be secure. “This places sensitive data, inadequately protected in an environment which then becomes a significantly more attractive target for attackers,” it said.
“We really don’t know if the data has been breached or not,” said a former senior policing source.
As well as risks, the report also listed mitigations. On the problem of cyber-attacks, it mandated that police servers should be repaired promptly, kept up to date, and have antivirus software.
To address the risk of “US government insiders” an...
