Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors

Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors

Vast troves of highly sensitive police data are lying on Microsoft cloud platforms which an official UK security assessment deemed to be vulnerable to “compromise” by foreign actors and the US government, a Guardian investigation can reveal.The files include criminal records, victim statements, internal emails and sensitive information held by more than 40 police forces across the UK.Some files exceed “official” classification, according to a police document seen by the Guardian, raising the possibility the information could be classed as “secret” or “top secret”.The cloud platform is Microsoft Azure, one of the main commercial offerings of the US tech company. It is used by businesses and governments globally and rests on a web of IT infrastructure – datacentres, networking gear, fibre optic cables – that spans more than 100 countries.In recent years, doubts have surfaced about how cloud platforms store data and whether they are truly secure.British police decided to put some of their most sensitive data on the Microsoftplatform in a 2017 meeting, a record of which was examined by the Guardian.In doing so, officers accepted that “US government insiders” would be able to see the data, and that it could be “transmitted worldwide”, with “the extent of this … unknown”.According to five specialists who reviewed the Guardian’s findings, the risks identified in that document persist today. Almost every UK police force now depends on Microsoft Azure, and the UK government spends at least £1.9bn on Microsoft software each year.“There’s no evidence that this has been properly understood,” said one source who has held senior roles in UK policing. The data is “some of the most sensitive that exists”, he added. “You’re talking about information that, if it gets into the wrong hands, or if the information is incorrect, [means] people can get hurt or may die.”When the Guardian approached the police about the possibility that sensitive information was not secure, they appeared to wave aside these risks, saying Britain’s contracts with Microsoft meant US authorities could not view data without express permission, and that the data it stored on Microsoft remained in the UK.These statements appeared to contradict public admissions by Microsoft, which said in a disclosure to Police Scotland in 2023 that data “can go outside the UK” and that it “cannot guarantee data sovereignty”.Microsoft said it “does not provide any government with direct or unfettered access to customer data”, and that it has not provided UK data in response to a US government request. It added that, like all US-based tech companies, it responded to US government requests made through valid legal processes.The threat of ‘US government insider attackers’In 2017, a senior police officer, Ian Dyson, chaired a meeting in which stakeholders considered 15 risks the UK would face if police forces decided to transfer their data to Microsoft’s global cloud.Ian Dyson, pictured in 2016. Photograph: Jamie SmithThat meeting considered both the police’s use of Microsoft’s software, such as Office 365, and the reliance on the cloud that underpins these services, Azure. Those risks, and the resulting police decisions, were set out in a summary document seen by the Guardian and signed off by Dyson.This was four years after the advent of a policy called “cloud first”. Introduced by the Cabinet Office in 2013, it became a government-wide effort to push almost all departments to migrate their data on to the “public cloud” – commercial offerings by tech companies, often based in the US. Departments that did not want to do this had to jump through burdensome administrative hoops.Dyson was the police commissioner of the City of London at the time, but he held another title: senior information risk owner for all of Britain, or the SIRO. It was his job to set the norms for how British police could safely handle their data.In their assessment, officers came to startling conclusions about what would happen if they put police data on Azure. Firstly, they considered it would be vulnerable to hackers: Microsoft’s software “carries vulnerabilities which will be exploited by cybercriminals and other threat actors in due course”.Separately, it added: “Police forces cannot be certain where their data will be processed or stored.“The hyper-scale and global nature of the Microsoft cloud means that police data, and metadata relating to police data could be transmitted and stored worldwide by Microsoft, and the extent of this will be unknown.”The document specifically identified the potential risk from what it described as “US government insiders”. It said: “There is a risk of compromise of sensitive data shared by, or taken from, Microsoft by the US government being released by US government insider attackers.”The document explained that the data intended for migration was sensitive. In fact, “a significant volume” of it exceeded the classification “official”. In the UK, this suggests it was either “official sensitive”, “secret”, or “top secret”.The assessment also suggested Microsoft’s platform was unable to guarantee this data would be secure. “This places sensitive data, inadequately protected in an environment which then becomes a significantly more attractive target for attackers,” it said.As well as risks, the report also listed mitigations. On the problem of cyber-attacks, it mandated that police servers should be repaired promptly, kept up to date, and have antivirus software.To address the risk of “US government insiders” and the concern that Microsoft might store UK policing data “worldwide” it suggested “applying Microsoft’s ‘out-of-the-box’ native encryption” and leaving the final decision about using Microsoft up to individual police chiefs.Several experts interviewed by the Guardian, including cloud computing specialists and engineers working for Microsoft, suggested these mitigations were inadequate. Microsoft’s internal encryption does not prevent its employees accessing UK police data; nor would it stop the US government obtaining British policing files.The National Police Chief’s Council (NPCC) said access to data stored on the cloud is limited to those with a genuine need to access it and that this is subject to strict controls. Despite that claim, a Microsoft engineer who reviewed the Guardian’s findings said the information “could be viewed by hundreds of people around the world, some of them not vetted, many of them not directly employed by Microsoft”.Despite the risks identified by the assessment, every police force in the UK put its data, wholly or in part, on Microsoft’s cloud. Some began migrating their information in 2017. A few forces, such as Police Scotland, are still finalising their adoption of the technology.The files cover the “full gamut of data: intelligence, body-worn video, digital evidence and case files, as well as the non-law enforcement data any organisation has”, said the source who held senior roles in UK policing.‘We do not expect any sharing … without permission’The UK government spends billions each year on services offered by three US tech companies: Amazon, Google and Microsoft.Up to 60% of its IT infrastructure is hosted on cloud platforms. Britain’s intelligence data is hosted on Amazon’s cloud services, as is its customs data. The Ministry of Defence uses Azure. There is “a deep dependency on US hyperscalers”, said Dave Michels, a researcher with the Cloud Legal Project, at Queen Mary University of London.This is the result of 13 years of decisions like Dyson’s. It is unclear if the potential consequences are broadly understood.When the Guardian approached the NPCC over the document signed by Dyson, it said: “UK policing as standard requires the use of UK-only datacentres,” but added that “on occasion” Microsoft employees could access the data “to provide support”.Asked whether the US government could access the data, a police spokesperson said they could not comment on the phrase “US government insiders”, because “terminology … changes continuously” and the document was “outdated”.“In line with the contract signed with Microsoft, we do not expect any sharing with the US government without the express permission of the UK government,” they said.Microsoft said: “The suggestion that use of Microsoft cloud services means customer data is inherently insecure or automatically exposed to foreign governments is inaccurate.” It said it had “never provided UK government data in response to any US or global authority request”.Two legal experts, as well as several Microsoft engineers who spoke anonymously to the Guardian, suggested these assertions did not give an accurate picture of the potential risks.By default, Microsoft’s cloud was “a global network of datacentres”, said Michels. It had facilities on every continent and this meant, generally, that data stored on it was stored everywhere: pieces of a single file could be held across multiple countries, from Sweden to Ethiopia.In recent years, Michels said, Microsoft had begun to offer clients in Europe greater assurances about where their data was stored, including assuring some customers that their data would remain within EU borders. But “the focus on data location is a bit of a red herring”, he said.This was because thousands of engineers from more than 100 countries maintained Microsoft’s systems. Some were directly employed by Microsoft, others worked for subcontractors in countries potentially hostile to the UK, from Israel to Egypt, China and Kazakhstan. “You’ve seen the list of their sub-processors of people who have access to customer data,” said Michels. “It’s a long list.”Some of the engineers could access data, such as UK police data, directly as part of customer support. Many more could see key features of what the data included.A Microsoft datacentre in the Netherlands. Photograph: Ramon van Flymen/EPAMicrosoft said it had “strong guardrails” around data access by engineers.Douwe Korff, a professor of international law at London Metropolitan University, said the police statement that“we do not expect any sharing [of our data] with the US government” was “typical lawyers’ wriggling”.“The risk is obvious, even though the providers of the cloud and the government both have an interest in talking it down,” he said.Michels said: “As a cloud customer, if you’re relying on a contractual commitment from a cloud provider not to hand over data when forced to under foreign law, that is not worth much more than the piece of paper it’s written on.”US law, including the Cloud Act, allows US authorities to access any data held by US cloud companies, including data held abroad. US authorities do not need a warrant to do this, and they can require US companies to not disclose such access to cloud customers.Microsoft, Amazon and Google have insisted they would fight such requests, said Korff. But there is “nothing that is legally binding” that would prevent them from sharing other governments’ data if US authorities demanded it.In response to a query from the Guardian, Microsoft said it “has never provided UK government data in response to any US or global authority request”. It added in a follow-up that it was bound by its “contractual commitments”.“If UK law prohibits us from turning over data to another government, that is a binding law that would govern our response to any hypothetical demand,” it said.‘We really don’t know if the data has been breached or not’The Guardian spoke to six people who have closely followed the country’s data storage arrangements over the past decade. Several of them said that senior leaders did not view dependence on US tech companies as a concern, and trusted them not to give data to US authorities.“Government security departments are painfully aware of all the risks, ” said Mark Butcher, a cloud expert who acts as a strategic adviser across government. “But the way that most senior leaders talk about it is: ‘Well, we’ve been reassured by Microsoft that it would never happen.’”But the source who has held senior policing roles said: “All the security guys I worked with when this policy came in expected a big breach by now, and we know it will take that to change the police’s position.“The truth is, however, the level of logging and information in the cloud systems would not necessarily tell us if there was a problem. We really don’t know if the data has been breached or not.”

Original Source

Read the full article at Theguardian →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.