The Information · Microsoft · Google · Amazon · United Kingdom · The Guardian Technology
Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
◌ Single Source
Vast troves of highly sensitive police data are lying on Microsoft cloud platforms which an official UK security assessment deemed to be vulnerable to “compromise” by foreign actors and the US government, a Guardian investigation can reveal.
Key facts
- In 2017, a senior police officer, Ian Dyson, chaired a meeting in which stakeholders considered 15 risks the UK would face if police forces decided to transfer their data to Microsoft’s global cloud
- There is “a deep dependency on US hyperscalers”, said Dave Michels, a researcher with the Cloud Legal Project, at Queen Mary University of London
- US law, including the Cloud Act, allows US authorities to access any data held by US cloud companies, including data held abroad
- The files include criminal records, victim statements, internal emails and sensitive information held by more than 40 police forces across the UK
Summary
The files include criminal records, victim statements, internal emails and sensitive information held by more than 40 police forces across the UK. Some files exceed “official” classification, according to a police document seen by the Guardian, raising the possibility the information could be classed as “secret” or “top secret”. The cloud platform is Microsoft Azure, one of the main commercial offerings of the US tech company. In recent years, doubts have surfaced about how cloud platforms store data and whether they are truly secure.