AI News Feed
Market watch
Cybersecurity

UK Police Data on Microsoft Azure Vulnerable to US and Foreign Compromise, Guardian Finds

Guardian investigation: sensitive UK police data on Microsoft Azure was deemed vulnerable to compromise by foreign actors and the US government.

Some of the files exceed the “official” classification, according to a police document seen by the Guardian, raising the possibility that the information could be classed as “secret” or “top secret.” Microsoft Azure is one of the main commercial offerings of the US technology company and is used by businesses and governments globally, resting on IT infrastructure that spans more than 100 countries.

British police decided to put some of their most sensitive data on the Microsoft platform at a meeting in 2017, a record of which was examined by the Guardian. The meeting considered 15 risks the UK would face if police forces transferred their data to Microsoft’s global cloud, covering both Microsoft software such as Office 365 and Azure. The summary document was signed off by Ian Dyson, then police commissioner of the City of London and also senior information risk owner for all of Britain, or SIRO.

In that assessment, officers accepted that “US government insiders” would be able to see the data and that it could be “transmitted worldwide,” with “the extent of this ... unknown.” The document said Microsoft’s software “carries vulnerabilities which will be exploited by cybercriminals and other threat actors in due course.” It also said police forces could not be certain where their data would be processed or stored. “The hyper-scale and global nature of the Microsoft cloud means that police data, and metadata relating to police data could be transmitted and stored worldwide by Microsoft, and the extent of this will be unknown,” it added.

The document specifically identified a risk from “US government insider attackers.” It said: “There is a risk of compromise of sensitive data shared by, or taken from, Microsoft by the US government being released by US government insider attackers.” The document explained that the data intended for migration was sensitive and that “a significant volume” of it exceeded the classification “official.”

The assessment came four years after the Cabinet Office introduced a “cloud first” policy in 2013, a government-wide effort to push almost all departments to migrate their data on to the “public cloud.” Departments that did not want to do this had to go through burdensome administrative hoops.

According to five specialists who reviewed the Guardian’s findings, the risks identified in the 2017 document persist today. Almost every UK police force now depends on Microsoft Azure, and the UK government spends at least £1.9bn on Microsoft software each year. “There’s no evidence that this has been properly understood,” said one source who has held senior roles in UK policing. The data is “some of the most sensitive that exists,” he added. “You’re talking about information that, if it gets into the wrong hands, or if the information is incorrect, [means] people can get hurt or may die.”

When the Guardian approached the police about the possibility that sensitive information was not secure, they appeared to wave aside these risks, saying Britain’s contracts with Microsoft meant US authorities could not view data without express permission and that the data it stored on Microsoft remained in the UK. Those statements appeared to contradict public admissions by Microsoft, which said in a disclosure to Police Scotland in 2023 that data “can go outside the UK” and that it “cannot guarantee data sovereignty.”

Microsoft said it “does not provide any government with direct or unfettered access to customer data,” and that it had not provided UK data in response to a US government request. It added that, like all US-based technology companies, it responded to US government requests made through valid legal processes.

Editor's Summary

A Guardian investigation has found that sensitive UK police data, including criminal records and victim statements, is stored on Microsoft Azure despite a 2017 UK assessment warning of possible compromise by foreign actors and US government insiders. The report says those risks remain as almost every UK police force relies on the platform, while police and Microsoft dispute key aspects of data access and sovereignty. The findings concern the security of police data held on global commercial cloud infrastructure.