
Sensitive UK police data vulnerable to âÂÂcompromiseâ by US government and foreign actors
Exclusive: Official UK security assessment found Microsoft cloud platform storing files was at potential risk from hostile hackers
Vast troves of highly sensitive police data are lying on Microsoft cloud platforms which an oï¬Âcial UK security assessment deemed to be vulnerable to âÂÂcompromiseâ by foreign actors and the US government, a Guardian investigation can reveal.
The files include criminal records, victim statements, internal emails and sensitive information held by more than 40 police forces across the UK.
Some files exceed âÂÂoï¬Âcialâ classification, according to a police document seen by the Guardian, raising the possibility the information could be classed as âÂÂsecretâ or âÂÂtop secretâÂÂ.
The cloud platform is Microsoft Azure, one of the main commercial offerings of the US tech company. It is used by businesses and governments globally and rests on a web of IT infrastructure â datacentres, networking gear, fibre optic cables â that spans more than 100 countries.
In recent years, doubts have surfaced about how cloud platforms store data and whether they are truly secure.
British police decided to put some of their most sensitive data on the Microsoft platform in a 2017 meeting, a record of which was examined by the Guardian.
In doing so, officers accepted that âÂÂUS government insidersâ would be able to see the data, and that it could be âÂÂtransmitted worldwideâÂÂ, with âÂÂthe extent of this ⦠unknownâÂÂ.
According to five specialists who reviewed the GuardianâÂÂs findings, the risks identified in that document persist today. Almost every UK police force now depends on Microsoft Azure, and the UK government spends at least ã1.9bn on Microsoft software each year.
âÂÂThereâÂÂs no evidence that this has been properly understood,â said one source who has held senior roles in UK policing. The data is âÂÂsome of the most sensitive that existsâÂÂ, he added. âÂÂYouâÂÂre talking about information that, if it gets into the wrong hands, or if the information is incorrect, [means] people can get hurt or may die.âÂÂ
When the Guardian approached the police about the possibility that sensitive information was not secure, they appeared to wave aside these risks, saying BritainâÂÂs contracts with Microsoft meant US authorities could not view data without express permission and that the data it stored on Microsoft remained in the UK.
These statements appeared to contradict public admissions by Microsoft, which said in a disclosure to Police Scotland in 2023 that data âÂÂcan go outside the UKâ and that it âÂÂcannot guarantee data sovereigntyâÂÂ.
Microsoft said it âÂÂdoes not provide any government with direct or unfettered access to customer dataâÂÂ, and that it had not provided UK data in response to a US government request. It added that, like all US-based tech companies, it responded to US government requests made through valid legal processes.
The threat of âÂÂUS government insider attackersâÂÂ
In 2017, a senior police oï¬Âcer, Ian Dyson, chaired a meeting in which stakeholders considered 15 risks the UK would face if police forces decided to transfer their data to MicrosoftâÂÂs global cloud.

That meeting considered both the policeâÂÂs use of MicrosoftâÂÂs software, such as Office 365, and the reliance on the cloud that underpins these services, Azure. Those risks, and the resulting police decisions, were set out in a summary document seen by the Guardian and signed off by Dyson.
This was four years after the advent of a policy called âÂÂcloud firstâÂÂ. Introduced by the Cabinet Office in 2013, it became a government-wide effort to push almost all departments to migrate their data on to the âÂÂpublic cloudâ â commercial offerings by tech companies, often based in the US. Departments that did not want to do this had to jump through burdensome administrative hoops.
Dyson was the police commissioner of the City of London at the time, but he held another title: senior information risk owner for all of Britain, or the SIRO. It was his job to set the norms for how British police could safely handle their data.
In their assessment, officers came to startling conclusions about what would happen if they put police data on Azure. Firstly, they considered it would be vulnerable to hackers: MicrosoftâÂÂs software âÂÂcarries vulnerabilities which will be exploited by cybercriminals and other threat actors in due courseâÂÂ.
Separately, it added: âÂÂPolice forces cannot be certain where their data will be processed or stored.
âÂÂThe hyper-scale and global nature of the Microsoft cloud means that police data, and metadata relating to police data could be transmitted and stored worldwide by Microsoft, and the extent of this will be unknown.âÂÂ
The document specifically identified the potential risk from what it described as âÂÂUS government insidersâÂÂ. It said: âÂÂThere is a risk of compromise of sensitive data shared by, or taken from, Microsoft by the US government being released by US government insider attackers.âÂÂ
The document explained that the data intended for migration was sensitive. In fact, âÂÂa significant volumeâ of it exceeded the classification âÂÂoï¬ÂcialâÂÂ. In the UK, this suggests it was either âÂÂoï¬Âcial sensitiveâÂÂ, âÂÂsecretâÂÂ, or âÂÂtop secretâÂÂ.
The assessment also suggested MicrosoftâÂÂs platform was unable to guarantee this data would be secure. âÂÂThis places sensitive data, inadequately protected in an environment which then becomes a significantly more attractive target for attackers,â it said.
As well as risks, the report also listed mitigations. On the problem of cyber-attacks, it mandated that police servers should be repaired promptly, kept up to date and have antivirus software.
To address the risk of âÂÂUS government insidersâ and the concern that Microsoft might store UK policing data âÂÂworldwideâ it suggested âÂÂapplying MicrosoftâÂÂs âÂÂout-of-the-boxâ native encryptionâ and leaving the final decision about using Microsoft up to individual police chiefs.
Several experts interviewed by the Guardian, including cloud computing specialists and engineers working for Microsoft, suggested these mitigations were inadequate. MicrosoftâÂÂs internal encryption does not prevent its employees accessing UK police data; nor would it stop the US government obtaining British policing files.
The National Police ChiefâÂÂs Council (NPCC) said access to data stored on the cloud is limited to those with a genuine need to access it and that this is subject to strict controls. Despite that claim, a Microsoft engineer who reviewed the GuardianâÂÂs findings said the information âÂÂcould be viewed by hundreds of people around the world, some of them not vetted, many of them not directly employed by MicrosoftâÂÂ.
Despite the risks identified by the assessment, every police force in the UK put its data, wholly or in part, on MicrosoftâÂÂs cloud. Some began migrating their information in 2017. A few forces, such as Police Scotland, are still finalising their adoption of the technology.
The files cover the âÂÂfull gamut of data: intelligence, body-worn video, digital evidence and case files, as well as the non-law enforcement data any organisation hasâÂÂ, said the source who held senior roles in UK policing.
âÂÂWe do not expect any sharing ⦠without permissionâÂÂ
The UK government spends billions each year on services oï¬Âered by three US tech companies: Amazon, Google and Microsoft.
Up to 60% of its IT infrastructure is hosted on cloud platforms. BritainâÂÂs intelligence data is hosted on AmazonâÂÂs cloud services, as is its customs data. The Ministry of Defence uses Azure. There is âÂÂa deep dependency on US hyperscalersâÂÂ, said Dave Michels, a researcher with the Cloud Legal Project, at Queen Mary University of London.
This is the result of 13 years of decisions like DysonâÂÂs. It is unclear if the potential consequences are broadly understood.
When the Guardian approached the NPCC over the document signed by Dyson, it said: âÂÂUK policing as standard requires the use of UK-only datacentres,â but added that âÂÂon occasionâ Microsoft employees could access the data âÂÂto provide supportâÂÂ.
Asked whether the US government could access the data, a police spokesperson said they could not comment on the phrase âÂÂUS government insidersâÂÂ, because âÂÂterminology ⦠changes continuouslyâ and the document was âÂÂoutdatedâÂÂ.
âÂÂIn line with the contract signed with Microsoft, we do not expect any sharing with the US government without the express permission of the UK government,â they added.
Microsoft said: âÂÂThe suggestion that use of Microsoft cloud services means customer data is inherently insecure or automatically exposed to foreign governments is inaccurate.â It said it had âÂÂnever provided UK government data in response to any US or global authority requestâÂÂ.
Two legal experts, as well as several Microsoft engineers who spoke anonymously to the Guardian, suggested these assertions did not give an accurate picture of the potential risks.
By default, MicrosoftâÂÂs cloud was âÂÂa global network of datacentresâÂÂ, said Michels. It had facilities on every continent and this meant, generally, that data stored on it was stored everywhere: pieces of a single file could be held across multiple countries, from Sweden to Ethiopia.
In recent years, Michels said, Microsoft had begun to offer clients in Europe greater assurances about where their data was stored, including assuring some customers that their data would remain within EU borders. But âÂÂthe focus on data location is a bit of a red herringâÂÂ, he said.
This was because thousands of engineers from more than 100 countries maintained MicrosoftâÂÂs systems. Some were directly employed by Microsoft, others worked for subcontractors in countries potentially hostile to the UK, from Israel to Egypt, China and Kazakhstan. âÂÂYouâÂÂve seen the list of their sub-processors of people who have access to customer data,â said Michels. âÂÂItâÂÂs a long list.âÂÂ
Some of the engineers could access data, such as UK police data, directly as part of customer support. Many more could see key features of what the data included.

Microsoft said it had âÂÂstrong guardrailsâ around data access by engineers.
Douwe Korff, a professor of international law at London Metropolitan University, said the police statement that âÂÂwe do not expect any sharing [of our data] with the US governmentâ was âÂÂtypical lawyersâ wrigglingâÂÂ.
âÂÂThe risk is obvious, even though the providers of the cloud and the government both have an interest in talking it down,â he said.
Michels said: âÂÂAs a cloud customer, if youâÂÂre relying on a contractual commitment from a cloud provider not to hand over data when forced to under foreign law, that is not worth much more than the piece of paper itâÂÂs written on.âÂÂ
US law, including the Cloud Act, allows US authorities to access any data held by US cloud companies, including data held abroad. US authorities do not need a warrant to do this, and they can require US companies to not disclose such access to cloud customers.
Microsoft, Amazon and Google have insisted they would fight such requests, said Korff. But there is âÂÂnothing that is legally bindingâ that would prevent them from sharing other governmentsâ data if US authorities demanded it.
In response to a query from the Guardian, Microsoft said it âÂÂhas never provided UK government data in response to any US or global authority requestâÂÂ. It added in a follow-up that it was bound by its âÂÂcontractual commitmentsâÂÂ.
âÂÂIf UK law prohibits us from turning over data to another government, that is a binding law that would govern our response to any hypothetical demand,â it said.
âÂÂThe security guys expected a big breach by nowâÂÂ
The Guardian spoke to six people who have closely followed the countryâÂÂs data storage arrangements over the past decade. Several of them said that senior leaders did not view dependence on US tech companies as a concern, and trusted them not to give data to US authorities.
âÂÂGovernment security departments are painfully aware of all the risks,â said Mark Butcher, a cloud expert who acts as a strategic adviser across government. âÂÂBut the way that most senior leaders talk about it is: âÂÂWell, weâÂÂve been reassured by Microsoft that it would never happen.âÂÂâÂÂ
But the source who has held senior policing roles said: âÂÂAll the security guys I worked with when this policy came in expected a big breach by now, and we know it will take that to change the policeâÂÂs position.
âÂÂThe truth is, however, the level of logging and information in the cloud systems would not necessarily tell us if there was a problem. We really donâÂÂt know if the data has been breached or not.âÂÂ
