Sensitive UK police data vulnerable to âcompromiseâ by US government and foreign actors
Vast troves of highly sensitive police data are lying on Microsoft cloud platforms which an oďŹcial UK security assessment deemed to be vulnerable to âcompromiseâ by foreign actors and the US government, a Guardian investigation can reveal.
The files include criminal records, victim statements, internal emails and sensitive information held by more than 40 police forces across the UK.
Some files exceed âoďŹcialâ classification, according to a police document seen by the Guardian, raising the possibility the information could be classed as âsecretâ or âtop secretâ.
The cloud platform is Microsoft Azure, one of the main commercial offerings of the US tech company. It is used by businesses and governments globally and rests on a web of IT infrastructure â datacentres, networking gear, fibre optic cables â that spans more than 100 countries.
In recent years, doubts have surfaced about how cloud platforms store data and whether they are truly secure.
British police decided to put some of their most sensitive data on the Microsoft platform in a 2017 meeting, a record of which was examined by the Guardian.
In doing so, officers accepted that âUS government insidersâ would be able to see the data, and that it could be âtransmitted worldwideâ, with âthe extent of this ⌠unknownâ.
According to five specialists who reviewed the Guardianâs findings, the risks identified in that document persist today. Almost every UK police force now depends on Microsoft Azure, and the UK government spends at least ÂŁ1.9bn on Microsoft software each year.
âThereâs no evidence that this has been properly understood,â said one source who has held senior roles in UK policing. The data is âsome of the most sensitive that existsâ, he added. âYouâre talking about information that, if it gets into the wrong hands, or if the information is incorrect, [means] people can get hurt or may die.â
When the Guardian approached the police about the possibility that sensitive information was not secure, they appeared to wave aside these risks, saying Britainâs contracts with Microsoft meant US authorities could not view data without express permission and that the data it stored on Microsoft remained in the UK.
These statements appeared to contradict public admissions by Microsoft, which said in a disclosure to Police Scotland in 2023 that data âcan go outside the UKâ and that it âcannot guarantee data sovereigntyâ.
Microsoft said it âdoes not provide any government with direct or unfettered access to customer dataâ, and that it had not provided UK data in response to a US government request. It added that, like all US-based tech companies, it responded to US government requests made through valid legal processes.
The threat of âUS government insider attackersâ
In 2017, a senior police oďŹcer, Ian Dyson, chaired a meeting in which stakeholders considered 15 risks the UK would face if police forces decided to transfer their data to Microsoftâs global cloud.
That meeting considered both the policeâs use of Microsoftâs software, such as Office 365, and the reliance on the cloud that underpins these services, Azure. Those risks, and the resulting police decisions, were set out in a summary document seen by the Guardian and signed off by Dyson.
This was four years after the advent of a policy called âcloud firstâ. Introduced by the Cabinet Office in 2013, it became a government-wide effort to push almost all departments to migrate their data on to the âpublic cloudâ â commercial offerings by tech companies, often based in the US. Departments that did not want to do this had to jump through burdensome administrative hoops.
Dyson was the police commissioner of the City of London at the time, but he held another title: senior information risk owner for all of Britain, or the SIRO. It was his job to set the norms for how British police could safely handle their data.
In their assessment, officers came to startling conclusions about what would happen if they put police data on Azure. Firstly, they considered it would be vulnerable to hackers: Microsoftâs software âcarries vulnerabilities which will be exploited by cybercriminals and other threat actors in due courseâ.
Separately, it added: âPolice forces cannot be certain where their data will be processed or stored.
âThe hyper-scale and global nature of the Microsoft cloud means that police data, and metadata relating to police data could be transmitted and stored worldwide by Microsoft, and the extent of this will be unknown.â
The document specifically identified the potential risk from what it described as âUS government insidersâ. It said: âThere is a risk of compromise of sensitive data shared by, or taken from, Microsoft by the US government being released by US government insider attackers.â
The document explained that the data intended for migration was sensitive. In fact, âa significant volumeâ of it exceeded the classification âoďŹcialâ. In the UK, this suggests it was either âoďŹcial sensitiveâ, âsecretâ, or âtop secretâ.
The assessment also suggested Microsoftâs platform was unable to guarantee this data would be secure. âThis places sensitive data, inadequately protected in an environment which then becomes a significantly more attractive target for attackers,â it said.
As well as risks, the report also listed mitigations. On the problem of cyber-attacks, it mandated that police servers should be repaired promptly, kept up to date and have antivirus software.
To address the risk of âUS government insidersâ and the concern that Microsoft might store UK policing data âworldwideâ it suggested âapplying Microsoftâs âout-of-the-boxâ native encryptionâ and leaving the final decision about using Microsoft up to individual police chiefs.
Several experts interviewed by the Guardian, including cloud computing specialists and engineers working for Microsoft, suggested these mitigations were inadequate. Microsoftâs internal encryption does not prevent its employees accessing UK police data; nor would it stop the US government obtaining British policing files.
The National Police Chiefâs Council (NPCC) said access to data stored on the cloud is limited to those with a genuine need to access it and that this is subject to strict controls. Despite that claim, a Microsoft engineer who reviewed the Guardianâs findings said the information âcould be viewed by hundreds of people around the world, some of them not vetted, many of them not directly employed by Microsoftâ.
Despite the risks identified by the assessment, every police force in the UK put its data, wholly or in part, on Microsoftâs cloud. Some began migrating their information in 2017. A few forces, such as Police Scotland, are still finalising their adoption of the technology.
The files cover the âfull gamut of data: intelligence, body-worn video, digital evidence and case files, as well as the non-law enforcement data any organisation hasâ, said the source who held senior roles in UK policing.
âWe do not expect any sharing ⌠without permissionâ
The UK government spends billions each year on services oďŹered by three US tech companies: Amazon, Google and Microsoft.
Up to 60% of its IT infrastructure is hosted on cloud platforms. Britainâs intelligence data is hosted on Amazonâs cloud services, as is its customs data. The Ministry of Defence uses Azure. There is âa deep dependency on US hyperscalersâ, said Dave Michels, a researcher with the Cloud Legal Project, at Queen Mary University of London.
This is the result of 13 years of decisions like Dysonâs. It is unclear if the potential consequences are broadly understood.
When the Guardian approached the NPCC over the document signed by Dyson, it said: âUK policing as standard requires the use of UK-only datacentres,â but added that âon occasionâ Microsoft employees could access the data âto provide supportâ.
Asked whether the US government could access the data, a police spokesperson said they could not comment on the phrase âUS government insidersâ, because âterminology ⌠changes continuouslyâ and the document was âoutdatedâ.
âIn line with the contract signed with Microsoft, we do not expect any sharing with the US government without the express permission of the UK government,â they added.
Microsoft said: âThe suggestion that use of Microsoft cloud services means customer data is inherently insecure or automatically exposed to foreign governments is inaccurate.â It said it had ânever provided UK government data in response to any US or global authority requestâ.
Two legal experts, as well as several Microsoft engineers who spoke anonymously to the Guardian, suggested these assertions did not give an accurate picture of the potential risks.
By default, Microsoftâs cloud was âa global network of datacentresâ, said Michels. It had facilities on every continent and this meant, generally, that data stored on it was stored everywhere: pieces of a single file could be held across multiple countries, from Sweden to Ethiopia.
In recent years, Michels said, Microsoft had begun to offer clients in Europe greater assurances about where their data was stored, including assuring some customers that their data would remain within EU borders. But âthe focus on data location is a bit of a red herringâ, he said.
This was because thousands of engineers from more than 100 countries maintained Microsoftâs systems. Some were directly employed by Microsoft, others worked for subcontractors in countries potentially hostile to the UK, from Israel to Egypt, China and Kazakhstan. âYouâve seen the list of their sub-processors of people who have access to customer data,â said Michels. âItâs a long list.â
Some of the engineers could access data, such as UK police data, directly as part of customer support. Many more could see key features of what the data included.
Microsoft said it had âstrong guardrailsâ around data access by engineers.
Douwe Korff, a professor of international law at London Metropolitan University, said the police statement that âwe do not expect any sharing [of our data] with the US governmentâ was âtypical lawyersâ wrigglingâ.
âThe risk is obvious, even though the providers of the cloud and the government both have an interest in talking it down,â he said.
Michels said: âAs a cloud customer, if youâre relying on a contractual commitment from a cloud provider not to hand over data when forced to under foreign law, that is not worth much more than the piece of paper itâs written on.â
US law, including the Cloud Act, allows US authorities to access any data held by US cloud companies, including data held abroad. US authorities do not need a warrant to do this, and they can require US companies to not disclose such access to cloud customers.
Microsoft, Amazon and Google have insisted they would fight such requests, said Korff. But there is ânothing that is legally bindingâ that would prevent them from sharing other governmentsâ data if US authorities demanded it.
In response to a query from the Guardian, Microsoft said it âhas never provided UK government data in response to any US or global authority requestâ. It added in a follow-up that it was bound by its âcontractual commitmentsâ.
âIf UK law prohibits us from turning over data to another government, that is a binding law that would govern our response to any hypothetical demand,â it said.
âThe security guys expected a big breach by nowâ
The Guardian spoke to six people who have closely followed the countryâs data storage arrangements over the past decade. Several of them said that senior leaders did not view dependence on US tech companies as a concern, and trusted them not to give data to US authorities.
âGovernment security departments are painfully aware of all the risks,â said Mark Butcher, a cloud expert who acts as a strategic adviser across government. âBut the way that most senior leaders talk about it is: âWell, weâve been reassured by Microsoft that it would never happen.ââ
But the source who has held senior policing roles said: âAll the security guys I worked with when this policy came in expected a big breach by now, and we know it will take that to change the policeâs position.
âThe truth is, however, the level of logging and information in the cloud systems would not necessarily tell us if there was a problem. We really donât know if the data has been breached or not.â
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.