An official United Kingdom security assessment has concluded that police files hosted on Microsoft cloud platforms were potentially vulnerable to compromise by foreign actors and the US government, a Guardian investigation has found. The material held on those platforms includes criminal records, victim statements, internal emails and other sensitive information from more than 40 police forces across the UK.
The assessment, compiled by UK security officials, flagged the Microsoft-hosted storage as presenting a potential risk of unauthorised access. It did not, according to the report, specify that a breach had occurred, but warned that the configuration and jurisdictional context of the cloud services left the data exposed to possible intrusion by hostile cyber actors and to legal access by foreign governments.
Police datasets on the cloud contain highly personal and operationally sensitive material, including witness and victim accounts, investigatory records and inter-force communications. The presence of such files on commercial cloud infrastructure has raised questions about the adequacy of safeguards, the legal frameworks governing cross-border access to data and the oversight of police use of third-party technology.
The disclosures are likely to prompt scrutiny from privacy advocates, police oversight bodies and lawmakers over how sensitive law-enforcement data is stored and who can obtain access. The assessment’s findings may lead to reviews of contracts, data protection practices and decisions about where and how police information is hosted, as well as potential steps to reduce exposure to external legal or cyber threats.
Microsoft, individual police forces and relevant UK authorities were not named as having commented in the material reviewed for the investigation. The assessment sits amid wider public debates about the security and sovereignty implications of using foreign cloud providers for sensitive government and policing operations.