Securityaffairs UK Police Data at Risk from US and Foreign Access via Microsoft Azure
Article Content
- •Sensitive UK police data is stored on Microsoft Azure, raising security concerns.
- •A 2017 assessment warned of risks from US government insiders accessing this data.
- •Experts assert that encryption does not prevent unauthorized access by Microsoft or US authorities.
A UK security assessment revealed that sensitive police data stored on Microsoft Azure is vulnerable to access by foreign actors and the US government. This data includes criminal records, victim statements, and internal communications from over 40 police forces. The 2017 assessment, led by then City of London police commissioner Ian Dyson, identified risks associated with the cloud platform, including potential exploitation by cybercriminals and insider threats from US government employees. Despite reassurances from UK police that data sovereignty is maintained, Microsoft has indicated that data can be accessed outside the UK under certain legal circumstances. Experts warn that encryption does not fully protect against unauthorized access. The UK government spends approximately £1.9 billion annually on Microsoft software, raising concerns about the security of sensitive information. The risks identified in 2017 remain relevant today, as nearly all UK police forces now rely on Microsoft Azure for data storage.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…